mirror of
				https://github.com/containous/traefik.git
				synced 2025-10-22 19:33:20 +03:00 
			
		
		
		
	Compare commits
	
		
			2815 Commits
		
	
	
		
			v1.6.0-rc2
			...
			v3.1.1
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
|  | f52a36ba12 | ||
|  | 2ffa6c6feb | ||
|  | 210400905f | ||
|  | ba6b4cbcc3 | ||
|  | 7dbd3f88f6 | ||
|  | 898eab20ac | ||
|  | 5a70910dce | ||
|  | 386c2ffb20 | ||
|  | 266a2d8b91 | ||
|  | 3ba53df005 | ||
|  | 5142733858 | ||
|  | ecdfb10653 | ||
|  | 0f4e72d522 | ||
|  | 70dd7cdc71 | ||
|  | c3e943658a | ||
|  | 4720caed04 | ||
|  | c5a6b49330 | ||
|  | a5df24a21d | ||
|  | f5a811d8fa | ||
|  | 4b4eaa49b5 | ||
|  | fc174062b6 | ||
|  | d700e95c21 | ||
|  | aa760b5a71 | ||
|  | a52c81fd91 | ||
|  | 127c0a7542 | ||
|  | 58dcbb43f9 | ||
|  | f32884d9b8 | ||
|  | 173a18fdc1 | ||
|  | 876899be4b | ||
|  | 89108972b6 | ||
|  | d42e75bb2e | ||
|  | 8d016f5e16 | ||
|  | 927f0bc01a | ||
|  | 900784a95a | ||
|  | 98c624bf1a | ||
|  | f3479f532b | ||
|  | 8946dd1898 | ||
|  | 2a0cfda90b | ||
|  | 12fae2ebb8 | ||
|  | 9758b1ce36 | ||
|  | fe4cca6e9c | ||
|  | b1b4e6b918 | ||
|  | 8cb1829698 | ||
|  | 2f9905061e | ||
|  | 0a7a6afd59 | ||
|  | b577b3a6ba | ||
|  | 230019eccf | ||
|  | 2090baa938 | ||
|  | b7de043991 | ||
|  | 9e0800f938 | ||
|  | e7d1a98c5e | ||
|  | 6f1bd54d86 | ||
|  | 983940ae60 | ||
|  | 6d8407893d | ||
|  | a8a92eb2a5 | ||
|  | 2798e18e18 | ||
|  | 61defcdd66 | ||
|  | ec638a741e | ||
|  | 097e71ad24 | ||
|  | eabcb3e1c0 | ||
|  | 53a8bd76f2 | ||
|  | 0e89c48e38 | ||
|  | 385ff5055c | ||
|  | b4f99ae3ac | ||
|  | a696f7c654 | ||
|  | 3ca667a3d4 | ||
|  | 27af1fb478 | ||
|  | e322184a98 | ||
|  | 69424a16a5 | ||
|  | f9f22b7b70 | ||
|  | b795f128d7 | ||
|  | 6706bb1612 | ||
|  | 3f48e6f8ef | ||
|  | 8ea339816a | ||
|  | 00b1d8b0bc | ||
|  | 21c6edcf58 | ||
|  | 5c48e3c96c | ||
|  | c23c3e0ed3 | ||
|  | b37aaea36d | ||
|  | 67f0700377 | ||
|  | 778dc22e14 | ||
|  | cdf0c8b3ec | ||
|  | 359477c583 | ||
|  | 28d40e7f3c | ||
|  | b368e71337 | ||
|  | dc752c7847 | ||
|  | 6155c900be | ||
|  | 6ca4c5da5c | ||
|  | 7eac92f49c | ||
|  | e6b1b05fdf | ||
|  | b452f37e08 | ||
|  | 8cff718c53 | ||
|  | bfda5e607f | ||
|  | 7fc56454ea | ||
|  | c0a2e6b4b6 | ||
|  | 0f0cc420e1 | ||
|  | 9250b5937d | ||
|  | e9bd2b45ac | ||
|  | 4406c337d4 | ||
|  | ed10bc5833 | ||
|  | e33bd6874f | ||
|  | 6e61fe0de1 | ||
|  | 05828bab07 | ||
|  | 0e215f9b61 | ||
|  | 7fdb1ff8af | ||
|  | 736f37cb58 | ||
|  | cff71ee496 | ||
|  | f02b223639 | ||
|  | d4d23dce72 | ||
|  | 5e4dc783c7 | ||
|  | 440cb11250 | ||
|  | 42920595ad | ||
|  | e68e647fd9 | ||
|  | 8b558646fc | ||
|  | f8e45a0b29 | ||
|  | d65de8fe6c | ||
|  | 5f2c00b438 | ||
|  | c2c1c3e09e | ||
|  | d8a778b5cd | ||
|  | d8cf90dade | ||
|  | 6a06560318 | ||
|  | a4aad5ce5c | ||
|  | 15973f5503 | ||
|  | a4150409c8 | ||
|  | aee515b930 | ||
|  | 05d2c86074 | ||
|  | b0d19bd466 | ||
|  | d99d2f95e6 | ||
|  | 8d2a2ff08f | ||
|  | 73e5dbbfe5 | ||
|  | ee3e7cbbec | ||
|  | 9d8fd24730 | ||
|  | f5d451d816 | ||
|  | f84e00e481 | ||
|  | fe0af1ec4b | ||
|  | 95312d5324 | ||
|  | e3729ec600 | ||
|  | 20d6c19c30 | ||
|  | 7a7b03eb01 | ||
|  | ea4f307fcd | ||
|  | a6b00608d2 | ||
|  | 7b649e2f0c | ||
|  | 52e95deee3 | ||
|  | 70968bc6a9 | ||
|  | da7bb5fc25 | ||
|  | 34bd611131 | ||
|  | b9b7527762 | ||
|  | 240b83b773 | ||
|  | 584839e00b | ||
|  | 099c7e9444 | ||
|  | 83a5c5cfbd | ||
|  | c1d9b9ee1f | ||
|  | d53f5f01a0 | ||
|  | 4e11bf3c38 | ||
|  | 1a266c661a | ||
|  | bda4f50eae | ||
|  | 19e6170fa5 | ||
|  | 0017471f0d | ||
|  | 76723b1288 | ||
|  | cef842245c | ||
|  | f69fd43122 | ||
|  | e5062cef42 | ||
|  | 998c6174cd | ||
|  | ac1753a614 | ||
|  | d3516aec31 | ||
|  | 2c6418e17a | ||
|  | 1ffbffb26a | ||
|  | fdf27eb644 | ||
|  | 945ff9b0f9 | ||
|  | bbd5846c6a | ||
|  | 9f145dbc28 | ||
|  | c84b510f0d | ||
|  | 2bc3fa7b4b | ||
|  | fc897f6756 | ||
|  | c31f5df854 | ||
|  | b636b21167 | ||
|  | 167bdb0d53 | ||
|  | 7f29595c0a | ||
|  | 3fcf265d80 | ||
|  | 618fb5f232 | ||
|  | d94e676083 | ||
|  | 141abce2d5 | ||
|  | fc875b38e0 | ||
|  | 39fe3869b6 | ||
|  | d582e01892 | ||
|  | 75790e0ab8 | ||
|  | 1391c35978 | ||
|  | 7bda07a422 | ||
|  | 9b6af61d1b | ||
|  | 5edac5eccd | ||
|  | 83e4abdb30 | ||
|  | 4e1e2f5ed0 | ||
|  | c06629459d | ||
|  | 05be441027 | ||
|  | 6c9687f410 | ||
|  | 5cf1b95c29 | ||
|  | 74daa4cbb3 | ||
|  | 709ff6fb09 | ||
|  | 4fd5fca34f | ||
|  | 31a93d5045 | ||
|  | 4cb5825d11 | ||
|  | 15f50553e9 | ||
|  | b4ca02da86 | ||
|  | 86be0a4e6f | ||
|  | 0e89a6bec7 | ||
|  | c5808af4d9 | ||
|  | c1ef742977 | ||
|  | 935d251b21 | ||
|  | 73769af0fe | ||
|  | 3b851a5ef2 | ||
|  | deab4dae8e | ||
|  | f7edb394f2 | ||
|  | baf687218c | ||
|  | 153765f99f | ||
|  | 5a2e233a15 | ||
|  | 453e21c7c9 | ||
|  | 8b759ab797 | ||
|  | 88a2020817 | ||
|  | c3545c620b | ||
|  | 1034646ae2 | ||
|  | 538f780a85 | ||
|  | b931c8ae9b | ||
|  | c5c61dbade | ||
|  | 1e7dbc70a0 | ||
|  | 6a2db4e4e9 | ||
|  | 1ea98d3d31 | ||
|  | 014fdfc4ec | ||
|  | b5ec787fb6 | ||
|  | 0c8778639a | ||
|  | 8f29398573 | ||
|  | 676de5fb68 | ||
|  | 063f8fae79 | ||
|  | efa6ca0fa1 | ||
|  | 4e831b920e | ||
|  | bc84fdd006 | ||
|  | d5cb9b50f4 | ||
|  | e11ff98608 | ||
|  | 9df04df334 | ||
|  | bb6cd581a6 | ||
|  | 8f9ad16f54 | ||
|  | 5d8b1949b7 | ||
|  | d7ec0cedbf | ||
|  | f1104ada65 | ||
|  | 3ba3ca6eb0 | ||
|  | 85039e0d54 | ||
|  | 9be523d772 | ||
|  | 8b77f0c2dd | ||
|  | d02be003ab | ||
|  | 4d539273ad | ||
|  | 40de310927 | ||
|  | 18203f57d2 | ||
|  | ef0e9c6f05 | ||
|  | d37ea3e882 | ||
|  | 3174c69c66 | ||
|  | f4f3dbe1f5 | ||
|  | 49f04f2772 | ||
|  | 03d2e35488 | ||
|  | aece9a1051 | ||
|  | 547cd81599 | ||
|  | b5251c6ac4 | ||
|  | 190b9b1afa | ||
|  | 9befe0dd51 | ||
|  | 683e2ee5c6 | ||
|  | 21da705ec9 | ||
|  | a3ac456199 | ||
|  | 9843757834 | ||
|  | f9831f5b1b | ||
|  | 177c4b0ed1 | ||
|  | bab48bed22 | ||
|  | 6cb2ff2af9 | ||
|  | 5e0855ecc7 | ||
|  | f57cee578f | ||
|  | 8da38ec0a5 | ||
|  | a6d462f6e8 | ||
|  | 6c19a9cb8f | ||
|  | 0eeb85d01d | ||
|  | 64ff214ff8 | ||
|  | 111f3716fa | ||
|  | 4e0a05406b | ||
|  | 39b0aa6650 | ||
|  | 319517adef | ||
|  | 7a315bb043 | ||
|  | 34d2a816c2 | ||
|  | 81ce45271d | ||
|  | 3a461d2f23 | ||
|  | 980dac4572 | ||
|  | ff7966f9cd | ||
|  | e78374aa29 | ||
|  | 3bbc560283 | ||
|  | ccf3a9995a | ||
|  | e522446909 | ||
|  | fea94a3393 | ||
|  | 4ddef9830b | ||
|  | 45bb00be04 | ||
|  | cd8d5b8f10 | ||
|  | eff294829f | ||
|  | a69c1ba3b7 | ||
|  | 9adf0fb638 | ||
|  | 56e2110dc5 | ||
|  | 5be13802dc | ||
|  | 7345afd8b6 | ||
|  | a84d5c0ef1 | ||
|  | 2a9471d278 | ||
|  | 0042562678 | ||
|  | 74ab88d47e | ||
|  | 6df9578ace | ||
|  | cd7d324295 | ||
|  | 0e92b02474 | ||
|  | 9662cdca64 | ||
|  | 3dfaa3d5fa | ||
|  | 60123a8f3f | ||
|  | 2a7b2ef772 | ||
|  | d51a2ce487 | ||
|  | 0a79643001 | ||
|  | e77a66c2ac | ||
|  | 6858dbdd07 | ||
|  | b2bb96390a | ||
|  | e29a142f6a | ||
|  | dae0491b61 | ||
|  | f4ddf25e41 | ||
|  | 35c704ace3 | ||
|  | 789046f162 | ||
|  | 186e3e1541 | ||
|  | 088fe3c270 | ||
|  | 553ef94047 | ||
|  | 12e50e20e6 | ||
|  | cd326654a7 | ||
|  | 3de29433f8 | ||
|  | 84516f962d | ||
|  | f92b03a44d | ||
|  | 085b70c94e | ||
|  | 0e66ed87f8 | ||
|  | d141e4a1ed | ||
|  | 679975beec | ||
|  | 8faed97e74 | ||
|  | 0b4c582088 | ||
|  | c7cd0df3b3 | ||
|  | 286181aa61 | ||
|  | 6a34f238ce | ||
|  | 4b2c763cf3 | ||
|  | d03d8d53fd | ||
|  | 8d0979bfd0 | ||
|  | e95fde5652 | ||
|  | ab7993428d | ||
|  | b966215e6c | ||
|  | b786f58f80 | ||
|  | 173154cf59 | ||
|  | 4acec60e72 | ||
|  | c3880a69ca | ||
|  | 4d63eb30f9 | ||
|  | 0ee377bc9f | ||
|  | dbc679dc30 | ||
|  | fc7f732029 | ||
|  | ba912e1a93 | ||
|  | 3216c8ab10 | ||
|  | 561c580701 | ||
|  | 3fd5c747a2 | ||
|  | b6b6cef3da | ||
|  | d651d1e7cf | ||
|  | 6f22b9e0a7 | ||
|  | f29325c679 | ||
|  | 57780d8004 | ||
|  | 46f4a8541e | ||
|  | 1d85515aac | ||
|  | 55e00be36e | ||
|  | d6457e6cbb | ||
|  | ca2b9e8e77 | ||
|  | d948784d38 | ||
|  | 1ddb0afb24 | ||
|  | f518676238 | ||
|  | db3e8a7f5a | ||
|  | 0bd367ebbd | ||
|  | f4dc298406 | ||
|  | 4f6c15cc14 | ||
|  | 3f93e9ea71 | ||
|  | eb585740a1 | ||
|  | 1709f3854c | ||
|  | ebde81e91c | ||
|  | 47faae25d7 | ||
|  | 7792d197e6 | ||
|  | deb4235028 | ||
|  | 7d66f439eb | ||
|  | 124ee3c48c | ||
|  | bed6069e82 | ||
|  | e29da5ad65 | ||
|  | 48de3b0230 | ||
|  | 00048a8351 | ||
|  | 2df5defd36 | ||
|  | aaa763b7af | ||
|  | 8a68ece2cc | ||
|  | 08b80c20f0 | ||
|  | d4daafa468 | ||
|  | 52d2d959af | ||
|  | 0a35fa096a | ||
|  | a7ef965412 | ||
|  | 0a861716d4 | ||
|  | 4fbe9b81ec | ||
|  | 5fd6913ee5 | ||
|  | 7741c68eaa | ||
|  | 18077ff69a | ||
|  | fa555d0d29 | ||
|  | 0e5898b2f8 | ||
|  | aae76408e2 | ||
|  | 9cc9ed6a0c | ||
|  | fecaec7a4a | ||
|  | e62fe64ec9 | ||
|  | 6885e410f0 | ||
|  | 68ed875966 | ||
|  | d1bdeb3a92 | ||
|  | 878e7de56a | ||
|  | 27353d0740 | ||
|  | 60bc47d00e | ||
|  | 606281a4a5 | ||
|  | c5f23493ab | ||
|  | db515195f0 | ||
|  | 9aa57f362b | ||
|  | 6977b68b72 | ||
|  | 8d8717d421 | ||
|  | cf1cbb24df | ||
|  | 981ad74870 | ||
|  | 021f37ff71 | ||
|  | 511762cbf3 | ||
|  | 466d7461b7 | ||
|  | 1522afe2ec | ||
|  | 9c73c4c584 | ||
|  | 8f206ce319 | ||
|  | 65c59c9a09 | ||
|  | e044e2b765 | ||
|  | 7805c683e3 | ||
|  | e38c0c3969 | ||
|  | 619045eb4b | ||
|  | 2cebd0a083 | ||
|  | c0e03ae17d | ||
|  | 9060522414 | ||
|  | bb4eb32b1c | ||
|  | 30f991effa | ||
|  | fc071a5ebe | ||
|  | 6082b22922 | ||
|  | 5635687a3e | ||
|  | a3f1009170 | ||
|  | 79c5f34156 | ||
|  | 928db9bc42 | ||
|  | c4bea197ab | ||
|  | e8878fe6ac | ||
|  | f344239bef | ||
|  | 4ed3964b35 | ||
|  | 11966c2098 | ||
|  | 0d1bb72306 | ||
|  | 4c9765b52d | ||
|  | 5f514b0d16 | ||
|  | 01f346f239 | ||
|  | be1b1a6489 | ||
|  | ae65d5ff78 | ||
|  | 7fc07c31a0 | ||
|  | f2eda3aa6d | ||
|  | ac9d88e5a2 | ||
|  | 8174860770 | ||
|  | 598caf6f78 | ||
|  | 77509b0913 | ||
|  | 8b47c5adf7 | ||
|  | a3bcf0f39e | ||
|  | be702c2b61 | ||
|  | 54f6144ef2 | ||
|  | a020ab640d | ||
|  | 7875826bd9 | ||
|  | f7be1e97df | ||
|  | 48a2c8e41c | ||
|  | 358f47443e | ||
|  | 3b9e155807 | ||
|  | 2083e4bc16 | ||
|  | c823879097 | ||
|  | 4bc2305ed3 | ||
|  | 99d779a546 | ||
|  | 6e460cd652 | ||
|  | 7c2af10bbd | ||
|  | 7af9d16208 | ||
|  | 598a257ae1 | ||
|  | b3f162a8a6 | ||
|  | 4aa3496092 | ||
|  | bbe6a5c07b | ||
|  | 20e47d9102 | ||
|  | 21c455cf20 | ||
|  | 667b2a4078 | ||
|  | 4ae07d91a4 | ||
|  | 7bdf13ebdc | ||
|  | 807feef176 | ||
|  | 7202038649 | ||
|  | dd710dbeb7 | ||
|  | f26e250648 | ||
|  | 80790cba17 | ||
|  | 2e6e5cbd03 | ||
|  | 241fb5093a | ||
|  | ab36ea7844 | ||
|  | cfef9d9df2 | ||
|  | 9ce69fbdef | ||
|  | 1a6dfe1f6b | ||
|  | e053eb6f17 | ||
|  | 780936eff9 | ||
|  | 0503253cfe | ||
|  | 39331e41a8 | ||
|  | 044dc6a221 | ||
|  | 38f5024ed0 | ||
|  | 479878503d | ||
|  | 6f6c1f7fec | ||
|  | e50bf21a84 | ||
|  | d66875f903 | ||
|  | 707f84e2e4 | ||
|  | f94298e867 | ||
|  | b995a11d63 | ||
|  | e1abf103c0 | ||
|  | f01a668d53 | ||
|  | 8cd4923e72 | ||
|  | cd90b9761a | ||
|  | e82976e001 | ||
|  | f0f5f41fb9 | ||
|  | c9e9e8dee2 | ||
|  | 0861c47e54 | ||
|  | 8bf68b7efd | ||
|  | e1e86763e3 | ||
|  | b22aef7fff | ||
|  | b9a175f5c2 | ||
|  | a2016a2953 | ||
|  | c38d405cfd | ||
|  | 8c98234c07 | ||
|  | d046af2e91 | ||
|  | 943238faba | ||
|  | 2b67f1f66f | ||
|  | 943811fad6 | ||
|  | 2ad1fd725a | ||
|  | 7129f03dc9 | ||
|  | 29b8b6911e | ||
|  | e7baf44a2e | ||
|  | 74ef79ea23 | ||
|  | 748254b6c5 | ||
|  | a08a428787 | ||
|  | 3eeea2bb2b | ||
|  | da93dab828 | ||
|  | c2dac39da1 | ||
|  | e54ee89330 | ||
|  | fdd3f2abef | ||
|  | 517917cd7c | ||
|  | d97d3a6726 | ||
|  | 6c75052a13 | ||
|  | a8df674dcf | ||
|  | abd569701f | ||
|  | 7e3fe48b80 | ||
|  | 8cf9385938 | ||
|  | 519ed8bde5 | ||
|  | 46a61ce9c8 | ||
|  | 778188ed34 | ||
|  | 88603810a8 | ||
|  | c7647b4938 | ||
|  | af71443b61 | ||
|  | c57876c116 | ||
|  | 0d81fac3fc | ||
|  | db287c4d31 | ||
|  | 4d86668af3 | ||
|  | b93141992e | ||
|  | 18d66d7432 | ||
|  | a3e4c85ec0 | ||
|  | bee86b5ac7 | ||
|  | 0ba51d62fa | ||
|  | 268d1edc8f | ||
|  | 580e7fa774 | ||
|  | 7c72780820 | ||
|  | 46c266661c | ||
|  | 61325d7b91 | ||
|  | 68e8eb2435 | ||
|  | 3f8aa13e68 | ||
|  | 08279047ae | ||
|  | 3dd4968c41 | ||
|  | ba1ca68977 | ||
|  | 81a5b1b4c8 | ||
|  | 52e6ce95cf | ||
|  | d547718fdd | ||
|  | 56f7515ecd | ||
|  | af4e74c39d | ||
|  | 27c02b5a56 | ||
|  | f6b7940b76 | ||
|  | f1b91a119d | ||
|  | 630de7481e | ||
|  | fadee5e87b | ||
|  | 35d8281f4d | ||
|  | 67d9c8da0b | ||
|  | 00de5c711a | ||
|  | b935c80dbd | ||
|  | 22c6630412 | ||
|  | 1a1cfd1adc | ||
|  | 240fb871b6 | ||
|  | b2c4221429 | ||
|  | d131ef57da | ||
|  | 97de552e06 | ||
|  | 281fa25844 | ||
|  | 454f552691 | ||
|  | 7258048403 | ||
|  | bd3eaf4f5e | ||
|  | 15f7472091 | ||
|  | a041a6b198 | ||
|  | 7582da9650 | ||
|  | 7a6bfd3336 | ||
|  | 1b9873cae9 | ||
|  | e86f21ae7b | ||
|  | ccbbd0d766 | ||
|  | 93212125e3 | ||
|  | be3b798dd6 | ||
|  | 8128d6ca26 | ||
|  | 194247caae | ||
|  | cd0654026a | ||
|  | 14ab1514dc | ||
|  | 40242294d8 | ||
|  | 996eccf5b7 | ||
|  | b39ce8cc58 | ||
|  | e9de061b84 | ||
|  | 33f0aed5ea | ||
|  | 0ca1c8aac3 | ||
|  | 2c550c284d | ||
|  | 87815586be | ||
|  | 09d6383621 | ||
|  | 188ef84c4f | ||
|  | a5c520664a | ||
|  | 39b0077725 | ||
|  | e2a9caf760 | ||
|  | bc79796c38 | ||
|  | b1db81d8ac | ||
|  | 38d7011487 | ||
|  | ae7db879d9 | ||
|  | dd34905ea9 | ||
|  | 3812e6f3cb | ||
|  | 627175694d | ||
|  | 82cf6c9577 | ||
|  | 63a1186d3e | ||
|  | f75f636e27 | ||
|  | 615dc7fd35 | ||
|  | 52b6b057f0 | ||
|  | 7b3faef4b3 | ||
|  | 7758880f3f | ||
|  | d04903edb2 | ||
|  | a63d5c95a8 | ||
|  | bb66950197 | ||
|  | c4cc30ccc6 | ||
|  | 9cd54baca4 | ||
|  | 7ac687a0a9 | ||
|  | 83ae1021f6 | ||
|  | 033fccccc7 | ||
|  | df99a9fb57 | ||
|  | 67e3bc6380 | ||
|  | d6b69e1347 | ||
|  | 4bd055cf97 | ||
|  | 4b291b2cf8 | ||
|  | 89870ad539 | ||
|  | 5bc03af75f | ||
|  | 30ec5c58fe | ||
|  | a4b447256b | ||
|  | 1c9a7b8c61 | ||
|  | d06573de6c | ||
|  | 6c2c561d8f | ||
|  | e5309a4601 | ||
|  | e9f98fb6eb | ||
|  | b351266b2d | ||
|  | fd95560c66 | ||
|  | 788f8fa951 | ||
|  | 89dc466b23 | ||
|  | ab8d7d2e78 | ||
|  | a002ccfce3 | ||
|  | 693d5da1b9 | ||
|  | 8ddc37d528 | ||
|  | 0cb2652f51 | ||
|  | fe8e7ab5b8 | ||
|  | d531963f95 | ||
|  | d578ed7327 | ||
|  | 10528c973a | ||
|  | 56a1ed4220 | ||
|  | 37b6edb28c | ||
|  | 44a2b85dba | ||
|  | 77c8d60092 | ||
|  | b33c8cec0b | ||
|  | 52df1d63fe | ||
|  | c84378d649 | ||
|  | 12dccc4fdd | ||
|  | 32e44816c9 | ||
|  | 23c74c9f2e | ||
|  | 9a82d96e68 | ||
|  | d9589878fb | ||
|  | 703de5331b | ||
|  | d3e4d56a0d | ||
|  | adf82d72ae | ||
|  | 25027d6df8 | ||
|  | e56dfeb7d5 | ||
|  | 5ca7fff7f6 | ||
|  | dfa1f3fc00 | ||
|  | b26c45af2b | ||
|  | 626da4c0ae | ||
|  | 9c02612f65 | ||
|  | b3f4f6bb21 | ||
|  | 2cac58d9c0 | ||
|  | a553085689 | ||
|  | 6dd63e1702 | ||
|  | 868ab7a5c8 | ||
|  | 23c26d64ee | ||
|  | 63f9ec9c38 | ||
|  | 40db06204b | ||
|  | 4755bb2f33 | ||
|  | 45453b20fa | ||
|  | 40d2421db9 | ||
|  | af749f1864 | ||
|  | 1576ad85b8 | ||
|  | 2a2ea759d1 | ||
|  | b4ee7bdcbe | ||
|  | 146991efda | ||
|  | ab94bbaece | ||
|  | 5a706296f2 | ||
|  | 5b3354b8ce | ||
|  | 7751fb24eb | ||
|  | f85f3b68aa | ||
|  | b361608693 | ||
|  | cdda9a18ab | ||
|  | 3686f95832 | ||
|  | 2cb011f595 | ||
|  | b7199a7a9b | ||
|  | 14eb56cf30 | ||
|  | ff2911d070 | ||
|  | f07fcd3d54 | ||
|  | 0e4b4c1a31 | ||
|  | 154d8470ab | ||
|  | c9520480c2 | ||
|  | 05c3486347 | ||
|  | 0231db05b4 | ||
|  | 4dc379c601 | ||
|  | 8f6463ba7a | ||
|  | aff334ffb4 | ||
|  | 28da781194 | ||
|  | 51a02caea3 | ||
|  | 839bc7b3a8 | ||
|  | 9c79fafeeb | ||
|  | c51e590591 | ||
|  | 9c4b336f3b | ||
|  | aa8fda5eae | ||
|  | 8b22101236 | ||
|  | 3c1d5e0393 | ||
|  | 03598d395b | ||
|  | 9d61cb64a2 | ||
|  | ba3f5b318c | ||
|  | 62e17c659e | ||
|  | 41748c3ae4 | ||
|  | 65a317010b | ||
|  | a887794313 | ||
|  | 77e1ce2877 | ||
|  | 470a4f6e5f | ||
|  | 94141233f0 | ||
|  | 467c8b31c3 | ||
|  | ff17ac53df | ||
|  | 55ba4356f2 | ||
|  | 804b0ff2f2 | ||
|  | 818541d4d7 | ||
|  | 1b199730d2 | ||
|  | f8f685193d | ||
|  | 6e535f8cef | ||
|  | 23340c46e6 | ||
|  | 5c15f5fe04 | ||
|  | ba7e9ed788 | ||
|  | 9ccc8cfb25 | ||
|  | 9810bde68b | ||
|  | 251798a778 | ||
|  | 91f4ccf087 | ||
|  | 73306a1533 | ||
|  | b3eb629785 | ||
|  | aa0b5466a9 | ||
|  | becee5e393 | ||
|  | 59e66dfce5 | ||
|  | 9c59df5e9c | ||
|  | 2a88b25712 | ||
|  | b952f814c1 | ||
|  | f90e3817e8 | ||
|  | 6d6f8b28d7 | ||
|  | 118d56fc40 | ||
|  | f352c34136 | ||
|  | fbf90e6981 | ||
|  | 607faace07 | ||
|  | 521109d3f2 | ||
|  | ec25bdb9f9 | ||
|  | 685962545a | ||
|  | 34d29e7a10 | ||
|  | 05f3e60366 | ||
|  | 5aa1220e5a | ||
|  | c1919c6b24 | ||
|  | 6349e2e28c | ||
|  | e642365613 | ||
|  | ac4086d0ac | ||
|  | d5ff301d90 | ||
|  | 575d4ab431 | ||
|  | ede2be1f66 | ||
|  | d134a993d0 | ||
|  | 86cc6df374 | ||
|  | 32920ca65c | ||
|  | 3ac708ddcb | ||
|  | 0dac0c3a5b | ||
|  | 9810120aff | ||
|  | ae6e844143 | ||
|  | a34e1c0747 | ||
|  | c29ed24a06 | ||
|  | 619621f239 | ||
|  | ff5cd9b592 | ||
|  | af855ef7b4 | ||
|  | 6559d63d3c | ||
|  | 4758cc0c8e | ||
|  | e4ed829661 | ||
|  | 2968e5b61b | ||
|  | 7d274e8088 | ||
|  | 6c2eb6eef3 | ||
|  | 95257d2ee1 | ||
|  | 707d355d4a | ||
|  | 73ba7ed2d2 | ||
|  | 55addfefc8 | ||
|  | 0ecd85cc66 | ||
|  | a9fe3f98c5 | ||
|  | 77b2a88819 | ||
|  | 44621ad28c | ||
|  | 232e2c1e7d | ||
|  | ad3625bef3 | ||
|  | 7c4bf602f0 | ||
|  | ffdd693ff6 | ||
|  | 85b0a47fe8 | ||
|  | 78822a8015 | ||
|  | 55cef21fbe | ||
|  | 2691ac1307 | ||
|  | a51851247e | ||
|  | 0e532a3634 | ||
|  | 883422dc21 | ||
|  | c9daf16388 | ||
|  | b22945e185 | ||
|  | 71150bcaaf | ||
|  | 8c56d1a338 | ||
|  | a49b537d9c | ||
|  | 45328ab719 | ||
|  | 4b755dc58d | ||
|  | 0f29e893f4 | ||
|  | e3adf93a74 | ||
|  | 0d7d5a0318 | ||
|  | 81f88dd998 | ||
|  | b6bfa905db | ||
|  | c0b0f3f0f7 | ||
|  | 16d7b89cb1 | ||
|  | a4560fa20d | ||
|  | fbdb6e6e78 | ||
|  | 8d58f33a28 | ||
|  | 9398222db7 | ||
|  | d2a2362be5 | ||
|  | 4c0a3721d0 | ||
|  | ba2d09f6fb | ||
|  | 7243e65b51 | ||
|  | 3bf4a8fbe2 | ||
|  | 23a6602cbf | ||
|  | 822b94c45d | ||
|  | 0a776c3fd5 | ||
|  | d7378a96ad | ||
|  | db4c6111fd | ||
|  | 2da7fa0397 | ||
|  | 0d58e8d1ad | ||
|  | dad76e0478 | ||
|  | 79aab5aab8 | ||
|  | b02c651961 | ||
|  | 0617a1b0e0 | ||
|  | 06749e71f2 | ||
|  | 6622027c7c | ||
|  | 401c171bbd | ||
|  | a1e766e180 | ||
|  | 63bb770b9c | ||
|  | b3de9a040b | ||
|  | a59dbc4c79 | ||
|  | 40deefa868 | ||
|  | 491de0cf64 | ||
|  | c7b24f4e9c | ||
|  | 27a7563e33 | ||
|  | 25725e9b2f | ||
|  | 819de02101 | ||
|  | ce851a5929 | ||
|  | 7e390ef516 | ||
|  | fb23bd5d26 | ||
|  | 6974f54bfd | ||
|  | aaf5aa4506 | ||
|  | 371b6e3c86 | ||
|  | 9297055ad8 | ||
|  | 9e96089da6 | ||
|  | a79868fadc | ||
|  | 84a0810546 | ||
|  | d9fbb5e25c | ||
|  | e97aa6515b | ||
|  | 6bcfba43c8 | ||
|  | 0c83ee736c | ||
|  | ca55dfe1c6 | ||
|  | 4da33c2bc2 | ||
|  | 2d56be0ebb | ||
|  | 5780dc2b15 | ||
|  | 764bf59d4d | ||
|  | 6742dd8454 | ||
|  | 3ac755bd2f | ||
|  | 7543709ecf | ||
|  | 3ed72c4e46 | ||
|  | 477fa15859 | ||
|  | 1048348ae6 | ||
|  | 390eb9cb61 | ||
|  | 5a1c936ede | ||
|  | 47ad6538f1 | ||
|  | 9be44d8330 | ||
|  | a4b354b33f | ||
|  | a70b864c55 | ||
|  | 3bd5fc0f90 | ||
|  | aabfb792af | ||
|  | e5e48d1cc1 | ||
|  | 42a110dd69 | ||
|  | 64af364b02 | ||
|  | cf14b8fa92 | ||
|  | e7dc6ec025 | ||
|  | f29e311b73 | ||
|  | a914ce2bd2 | ||
|  | b42a7c89e7 | ||
|  | 67483c1b17 | ||
|  | 4071f1e7f2 | ||
|  | 577709fff3 | ||
|  | 8cd45476ac | ||
|  | cf14504fd5 | ||
|  | b84829336d | ||
|  | ba822acb23 | ||
|  | d969e59911 | ||
|  | 936b6148ff | ||
|  | a9776ceafc | ||
|  | e471239955 | ||
|  | 2e8156bfaa | ||
|  | f5dd233a3b | ||
|  | 48ce6c32c1 | ||
|  | 4990239855 | ||
|  | 5e2c929322 | ||
|  | 2b5355c849 | ||
|  | f21f71786a | ||
|  | fc7f109cb2 | ||
|  | a711f0d037 | ||
|  | 98fc6ca441 | ||
|  | c10f1a3a36 | ||
|  | da092e653d | ||
|  | bf29417136 | ||
|  | 79a14ce992 | ||
|  | 99ce26f7b1 | ||
|  | 16250361c3 | ||
|  | be44385b42 | ||
|  | 54c77ecb54 | ||
|  | a30f0dcabd | ||
|  | efef7dce4f | ||
|  | 1c9e4c6050 | ||
|  | 89cd9e8ddd | ||
|  | 92093a8c09 | ||
|  | d970813c20 | ||
|  | f69982aa9d | ||
|  | 82fdc569c2 | ||
|  | def0c1a526 | ||
|  | 93de7cf0c0 | ||
|  | ef2d03d96e | ||
|  | 321c9421ea | ||
|  | 5a225b4196 | ||
|  | 95fabeae73 | ||
|  | 525a6cf5b2 | ||
|  | 27ec0912d5 | ||
|  | 83a7f10c75 | ||
|  | 0a5c9095ac | ||
|  | 0a31225e65 | ||
|  | db4a92d877 | ||
|  | 9df053e3f5 | ||
|  | 1f17731369 | ||
|  | 8e32d1913b | ||
|  | e10a82a501 | ||
|  | ce47f200d5 | ||
|  | 95dc43ce4a | ||
|  | d91eefa74f | ||
|  | ffdfc13461 | ||
|  | a13b03ef3d | ||
|  | 69d504c905 | ||
|  | bda7e025a2 | ||
|  | 596f04eae8 | ||
|  | b39d226fb8 | ||
|  | 20dfb91948 | ||
|  | e033355225 | ||
|  | 56ed45ae70 | ||
|  | d3ff0c2cd4 | ||
|  | 566b205758 | ||
|  | b537ccdb0c | ||
|  | d9b8435a7d | ||
|  | c0ba4d177f | ||
|  | 7377ab7b95 | ||
|  | 207ac94ed0 | ||
|  | fe32a7e584 | ||
|  | 25e12aee14 | ||
|  | 85dd45cb81 | ||
|  | 32340252b2 | ||
|  | 5d716f0149 | ||
|  | 918a343557 | ||
|  | 969dd088a2 | ||
|  | 89001ae9a4 | ||
|  | c99221fa34 | ||
|  | 9ef3fc84f9 | ||
|  | d28bcf24e5 | ||
|  | 8d739c411b | ||
|  | 46c1600ada | ||
|  | 126b32c579 | ||
|  | 380514941c | ||
|  | 61ceb7a32c | ||
|  | 07a3c37a23 | ||
|  | c7e13eb082 | ||
|  | 6906a022ca | ||
|  | 8f0832d340 | ||
|  | bda0dba131 | ||
|  | 76867e39ea | ||
|  | 6f8e8ea252 | ||
|  | 8e7881094f | ||
|  | 7d09132a5c | ||
|  | 6f4a7fb604 | ||
|  | 6e28db513c | ||
|  | 2084201c8f | ||
|  | 70359e5d27 | ||
|  | a72d124551 | ||
|  | 7ff13c3e3e | ||
|  | 55360c1eaf | ||
|  | 60ff50a675 | ||
|  | ba3967aa16 | ||
|  | fffa413121 | ||
|  | c011bdfdd8 | ||
|  | 4235cef1b2 | ||
|  | 871e04cb12 | ||
|  | 287cebb498 | ||
|  | 6c8d200373 | ||
|  | 0ac6f80b50 | ||
|  | 2b73860ea5 | ||
|  | ddcb003b3b | ||
|  | be52c5abb1 | ||
|  | f81ceaef8a | ||
|  | eb6c5fc34d | ||
|  | 4fc16f26a3 | ||
|  | 234d35f592 | ||
|  | 352a72a5d7 | ||
|  | 4d1ce986a6 | ||
|  | 531a8ff248 | ||
|  | 2644c1f598 | ||
|  | fa53f7ec85 | ||
|  | e05574af58 | ||
|  | fcfc976b13 | ||
|  | 78180a5fa7 | ||
|  | 3445abe7ac | ||
|  | e0b442a48b | ||
|  | bd1c84755b | ||
|  | a7194e96e0 | ||
|  | 2bd60f9e60 | ||
|  | 35a40c8727 | ||
|  | 7f62667569 | ||
|  | fd4ba585ee | ||
|  | 81eb46e36d | ||
|  | b7700e77bf | ||
|  | e73dd31619 | ||
|  | 187ec26d8e | ||
|  | ef9b79f85c | ||
|  | 32d88a977d | ||
|  | 547c380961 | ||
|  | 848e23b489 | ||
|  | d63cb1b4d6 | ||
|  | c45de0d8bc | ||
|  | 5c18967f06 | ||
|  | e78f172f02 | ||
|  | 4fc077a5d2 | ||
|  | 7f307d60c4 | ||
|  | b386964abc | ||
|  | 817ac8f256 | ||
|  | c76d58d532 | ||
|  | 4b456f3b76 | ||
|  | 319e3065f0 | ||
|  | a48a8a97a1 | ||
|  | 8be434aaad | ||
|  | d9fc775084 | ||
|  | f25139424a | ||
|  | 2d95c37ea4 | ||
|  | e12630ef06 | ||
|  | 48bd279311 | ||
|  | 36ffdf548d | ||
|  | a5b169c563 | ||
|  | bc5e621683 | ||
|  | 1e69939532 | ||
|  | d8156ef625 | ||
|  | c2c4dc9b58 | ||
|  | ffd4e207a4 | ||
|  | bd3271aff0 | ||
|  | 0664f5a9ca | ||
|  | c515ace328 | ||
|  | 8d4620dc53 | ||
|  | 16f65f669b | ||
|  | 2a2f7f783f | ||
|  | 6ae50389e6 | ||
|  | 87fd51d7ec | ||
|  | 7e43e5615e | ||
|  | 985f8778e9 | ||
|  | 3a180e2afc | ||
|  | 2f47bb0df6 | ||
|  | 7e0f0d9d11 | ||
|  | e1f5866989 | ||
|  | 3c1ed0d9b2 | ||
|  | 10ab39c33b | ||
|  | 3072354ca5 | ||
|  | 14499cd6e5 | ||
|  | 5d3dc3348e | ||
|  | ca2ff214c4 | ||
|  | f8db285d5d | ||
|  | 1f880662d6 | ||
|  | febab86682 | ||
|  | 8070dfef45 | ||
|  | fc69f882c5 | ||
|  | 838a8e18d3 | ||
|  | 5e3e47b484 | ||
|  | 6d8512bda0 | ||
|  | cd68cbd3ea | ||
|  | 55845c95bb | ||
|  | a243ac4dde | ||
|  | a01cbb42c7 | ||
|  | b5da5760a2 | ||
|  | c190b160e9 | ||
|  | ce2e02b690 | ||
|  | 5dab09c42b | ||
|  | 03b08d67f0 | ||
|  | 5841c9a7a5 | ||
|  | ed9b1bea3f | ||
|  | dca348359b | ||
|  | cf0759a48f | ||
|  | c9df233d24 | ||
|  | 99a23b0414 | ||
|  | 95e0633b2f | ||
|  | 5ca210fa60 | ||
|  | 2ccdc419d0 | ||
|  | 9af0e705a5 | ||
|  | 0a3e40332a | ||
|  | a758d18e51 | ||
|  | f15d05b22f | ||
|  | fc9f41b955 | ||
|  | fd1eae4f07 | ||
|  | 51ee77b96f | ||
|  | b03c5ff5ce | ||
|  | 521fed1fea | ||
|  | 679def0151 | ||
|  | 2560626419 | ||
|  | e5024d5d0a | ||
|  | c10c7619d3 | ||
|  | dd04c432e9 | ||
|  | b1fd3b8fc7 | ||
|  | 456df0fc19 | ||
|  | 526f493e12 | ||
|  | 5632ee6378 | ||
|  | 1680f00091 | ||
|  | 376b6f90d9 | ||
|  | 21c0195d29 | ||
|  | 56f845c71a | ||
|  | d6d639d4d7 | ||
|  | e1e1fd640c | ||
|  | 2408eeceba | ||
|  | 6ae194934d | ||
|  | 63ef0f1cee | ||
|  | de2437cfec | ||
|  | 32e08f3510 | ||
|  | 40f21f41e1 | ||
|  | ee12424795 | ||
|  | 0b48d5d0d2 | ||
|  | 080cf98e51 | ||
|  | dc8d5ef744 | ||
|  | 70a02158e5 | ||
|  | ab71dad51a | ||
|  | 0624cefc10 | ||
|  | 56b26421a5 | ||
|  | ea8ba87aeb | ||
|  | 08b258a2cb | ||
|  | ac486d3d1d | ||
|  | e096bf6b62 | ||
|  | e28b33b53b | ||
|  | 5814ba5322 | ||
|  | be81ce244e | ||
|  | d3a3aeb0fc | ||
|  | fe6acdf4d2 | ||
|  | 702e0a461a | ||
|  | 46d6da4fce | ||
|  | aa61835b78 | ||
|  | 2a1e46c8b6 | ||
|  | cb4fb973b2 | ||
|  | 513f6e9a68 | ||
|  | ad980334d1 | ||
|  | d13d078351 | ||
|  | 947798b44c | ||
|  | ed427616d4 | ||
|  | 297921182c | ||
|  | 31a5f3591f | ||
|  | 32655b5b16 | ||
|  | 8947f85ddd | ||
|  | a513a05b7a | ||
|  | 1e716a93ff | ||
|  | 06fc2c505f | ||
|  | 6fcea91d1f | ||
|  | 93d099a2f0 | ||
|  | 29908098e4 | ||
|  | e5983d96f7 | ||
|  | 08e6ae07af | ||
|  | 49b46a9a3f | ||
|  | 36c316f39c | ||
|  | 7e76abc067 | ||
|  | 702e301990 | ||
|  | b1e11f3e88 | ||
|  | 09d5f59701 | ||
|  | 3c8675bb8b | ||
|  | 71ca237478 | ||
|  | 0e4b6d36fd | ||
|  | e898080460 | ||
|  | bdba7d3adf | ||
|  | 606b43dc51 | ||
|  | 2e7833df49 | ||
|  | ec0d03658d | ||
|  | 992d4c1b94 | ||
|  | d2d7cf14e5 | ||
|  | e658712d53 | ||
|  | 40cd6ada4f | ||
|  | c843c182e4 | ||
|  | c35a8bdb15 | ||
|  | dd0701dd16 | ||
|  | 32500773b8 | ||
|  | e7d3f4316f | ||
|  | 438eec720a | ||
|  | 4b38d7368f | ||
|  | dce6a86900 | ||
|  | dc9c558c06 | ||
|  | b8a466c571 | ||
|  | bae28c5f57 | ||
|  | 1b21f0723f | ||
|  | 911c439858 | ||
|  | f81f85cea2 | ||
|  | 1325cc5cd0 | ||
|  | 951d61bfcd | ||
|  | 0937cba870 | ||
|  | 5597d7633d | ||
|  | 502c88ee3f | ||
|  | 5ef6297daa | ||
|  | 9e33e23b8b | ||
|  | 16d00ccffb | ||
|  | d211437d6c | ||
|  | 7996a42f76 | ||
|  | f482e5e84a | ||
|  | 447c3567b4 | ||
|  | 3c5e6fe7f8 | ||
|  | bf4a578bbb | ||
|  | 4cabea069d | ||
|  | c53033a778 | ||
|  | ea8642e2a1 | ||
|  | 73cea2d303 | ||
|  | 96a3468791 | ||
|  | 2065f4c003 | ||
|  | 9a931e4dc9 | ||
|  | 49ec62c757 | ||
|  | a371f971fb | ||
|  | 5f9a84fc8b | ||
|  | 2461e36ed4 | ||
|  | 1305bf49a5 | ||
|  | da0a16e122 | ||
|  | fb10687168 | ||
|  | f0d78471af | ||
|  | a90b2a672e | ||
|  | 2bbb6fc427 | ||
|  | 2747e240c1 | ||
|  | 4b370930b5 | ||
|  | c74918321d | ||
|  | b05a5c818d | ||
|  | 41d22ef17e | ||
|  | bbee63fcf3 | ||
|  | b1ddd0e038 | ||
|  | 8c5dc3b5cb | ||
|  | afa05329d9 | ||
|  | dbbff393e1 | ||
|  | f742671bbe | ||
|  | 0dae829080 | ||
|  | e62a00a3f5 | ||
|  | ab4c93dd2f | ||
|  | ed5321999c | ||
|  | fb21e3bb5c | ||
|  | 3595292f7f | ||
|  | 47fb6e036a | ||
|  | 92886c46ea | ||
|  | 83fa3f4cc8 | ||
|  | c24f75ce0b | ||
|  | 63929b0341 | ||
|  | fc7ec17905 | ||
|  | e5a01c7cc8 | ||
|  | 0509b6fdb9 | ||
|  | 60d87f3c64 | ||
|  | 5d800ba5fe | ||
|  | 759d17547a | ||
|  | d4f0a9ff62 | ||
|  | c4fa96c41e | ||
|  | f54136b602 | ||
|  | 5dd1728bf8 | ||
|  | da1c9f48b7 | ||
|  | 0ec0e37532 | ||
|  | 544dc2eaa5 | ||
|  | a3327c4430 | ||
|  | f8ae972e70 | ||
|  | 3ff83fc1f8 | ||
|  | 63f65e5b2a | ||
|  | 3140a4e0cd | ||
|  | 31038e0e12 | ||
|  | ac8e47579b | ||
|  | ec0075e0d0 | ||
|  | 7900d266b1 | ||
|  | c21597c593 | ||
|  | ea418aa7d8 | ||
|  | 5487015a83 | ||
|  | 418cccd307 | ||
|  | 2a0760412c | ||
|  | eebbe64b36 | ||
|  | 42d8e6d60d | ||
|  | 7ba907f261 | ||
|  | c72769e2ea | ||
|  | 02d856b8a5 | ||
|  | 0d15ac8861 | ||
|  | 134a767a7f | ||
|  | 7403b6fb82 | ||
|  | 64a65cadf3 | ||
|  | 121eaced49 | ||
|  | a488430f23 | ||
|  | b5db753e11 | ||
|  | b0aa27db31 | ||
|  | 512ed086bd | ||
|  | 76e35a09b7 | ||
|  | d2c1d39d42 | ||
|  | e9cccf6504 | ||
|  | 1c505903ff | ||
|  | 53ed8e04ae | ||
|  | 2112de6f15 | ||
|  | be0845af02 | ||
|  | f83a57b3da | ||
|  | 08264749f0 | ||
|  | a75819cae3 | ||
|  | 9fb32a47ca | ||
|  | 4f43c9ebb4 | ||
|  | 9177982334 | ||
|  | 84b125bdde | ||
|  | 52eeff9f9f | ||
|  | 0fcccd35ff | ||
|  | 598dcf6b62 | ||
|  | 459200dd01 | ||
|  | af22cabc6f | ||
|  | 920e82f11a | ||
|  | 520fcf82ae | ||
|  | 9bdf9e1e02 | ||
|  | 3a45f05e36 | ||
|  | 8e3e387be7 | ||
|  | 267d0b7b5a | ||
|  | 74d1d55051 | ||
|  | 3a8cb3f010 | ||
|  | f5b290b093 | ||
|  | d38d11f02e | ||
|  | af04e92cf2 | ||
|  | 4ea1c98ac9 | ||
|  | 05333b9579 | ||
|  | 49cdb67ddc | ||
|  | b5198e63c4 | ||
|  | db007efe00 | ||
|  | 699cf71652 | ||
|  | a0c02f62a3 | ||
|  | ff7b814edc | ||
|  | 015f24a901 | ||
|  | 4fccde84bd | ||
|  | ea459e9af0 | ||
|  | 2dd5a53db2 | ||
|  | fc97ea7ee0 | ||
|  | 582d2540af | ||
|  | 6ad79dcd45 | ||
|  | 721896ba70 | ||
|  | 228270414c | ||
|  | 2683df7b5b | ||
|  | 3e61d1f233 | ||
|  | 04c07227f2 | ||
|  | 2e8d99c5b8 | ||
|  | c07301473b | ||
|  | b1ba42410b | ||
|  | b80f89e3db | ||
|  | edb15a9346 | ||
|  | 714a4d4f2d | ||
|  | 5c853766e8 | ||
|  | 3567ae88ad | ||
|  | afcec56be4 | ||
|  | d2435cf43b | ||
|  | 556f7608db | ||
|  | a4df4b028e | ||
|  | 63683d35fc | ||
|  | 495344591f | ||
|  | 4e508499da | ||
|  | 326be29568 | ||
|  | e4a3df3516 | ||
|  | 3506cbd5e9 | ||
|  | ab13019bde | ||
|  | ddc663eac0 | ||
|  | fc7002fbab | ||
|  | f2e53a3569 | ||
|  | c5b4e589ff | ||
|  | 5e63ab619e | ||
|  | c9bbfa1272 | ||
|  | 050968cbac | ||
|  | 8ca0d804d8 | ||
|  | 54e5a3607e | ||
|  | cd947ae822 | ||
|  | 2477e18c87 | ||
|  | ef08e8b8a0 | ||
|  | f59bf16e82 | ||
|  | 118c31eb8d | ||
|  | 476f16f0aa | ||
|  | b40d35b779 | ||
|  | 8e016cf672 | ||
|  | 7e482e9f8b | ||
|  | 6445befe87 | ||
|  | 86c099d629 | ||
|  | 79af433381 | ||
|  | c0f1e74bed | ||
|  | 9df89e66e3 | ||
|  | 660375d6e4 | ||
|  | 498e8545b6 | ||
|  | 230c2e5cc2 | ||
|  | 3e60863e2d | ||
|  | 4592626bbb | ||
|  | b980c87eff | ||
|  | 0f7c322623 | ||
|  | 76f42a3013 | ||
|  | 93b3d601d5 | ||
|  | 56329e89bb | ||
|  | 5c8b8149eb | ||
|  | 6075f7e8fd | ||
|  | ddf53494f0 | ||
|  | cd1f03d4f4 | ||
|  | 8474a61f21 | ||
|  | 4ad0ab5433 | ||
|  | 66d151df77 | ||
|  | 2045b250fd | ||
|  | 1dbee90d34 | ||
|  | eb7a6d925b | ||
|  | 3678bd5a93 | ||
|  | 2d1a973ee5 | ||
|  | 322f7b2ad4 | ||
|  | 41aa2672cd | ||
|  | f3090a452a | ||
|  | 52790d3c37 | ||
|  | 3677252e17 | ||
|  | 235d1d655d | ||
|  | 29bd6faa18 | ||
|  | 69c0f38305 | ||
|  | 0399d0c4d6 | ||
|  | 3db47f0adc | ||
|  | 483e2c43cf | ||
|  | 3e3b7238e0 | ||
|  | 532b5865de | ||
|  | 54b94f29e1 | ||
|  | b67a7215f6 | ||
|  | e424cc7608 | ||
|  | 229008e76a | ||
|  | 584f4bc596 | ||
|  | 1502d20def | ||
|  | eecc2f4dd7 | ||
|  | 6fc110a71a | ||
|  | ca6b46533a | ||
|  | a1fe29347a | ||
|  | 449afea4fc | ||
|  | 6e5dd35ee3 | ||
|  | 0d5d14d41a | ||
|  | 3a42e457cf | ||
|  | 5b05c990b0 | ||
|  | 9df0a6208b | ||
|  | 3214904cc7 | ||
|  | ec775a016a | ||
|  | a2ca235fee | ||
|  | de458b7357 | ||
|  | 7c039ca223 | ||
|  | 3942962ef5 | ||
|  | 675655d437 | ||
|  | dafb14ff37 | ||
|  | fc52d1cfba | ||
|  | fdf2a68a11 | ||
|  | 3908ef611a | ||
|  | e63db782c1 | ||
|  | a6c6127e33 | ||
|  | 207d0bec78 | ||
|  | 1443c8d4c6 | ||
|  | a136c46148 | ||
|  | bbbc18fd84 | ||
|  | 2c7f6e4def | ||
|  | dcd0cda0c6 | ||
|  | ff16925f63 | ||
|  | 0b7aaa3643 | ||
|  | 44a244b1cb | ||
|  | 1dc6f39b55 | ||
|  | 45f52ca29c | ||
|  | fae2d93525 | ||
|  | 25b74ce1f3 | ||
|  | 4957e498af | ||
|  | 54ca1abd2b | ||
|  | 8f2951b275 | ||
|  | 720bef97e6 | ||
|  | c42f1b7a50 | ||
|  | 0186c31d59 | ||
|  | 58bf1a2ca5 | ||
|  | 4a31544024 | ||
|  | cb6ec507e2 | ||
|  | 1ef93fead7 | ||
|  | 285ded6e49 | ||
|  | 6e4f5821dc | ||
|  | a3df5b9a94 | ||
|  | 04f0ebf776 | ||
|  | 0e97a3becd | ||
|  | 77a0cef9ce | ||
|  | 143e9b6f9c | ||
|  | 06dcf8d8aa | ||
|  | c315b4e064 | ||
|  | 73ca7ad0c1 | ||
|  | d7f517fbf5 | ||
|  | b10cb84f33 | ||
|  | a55f0cabdd | ||
|  | d73c7ccf50 | ||
|  | 2b35397169 | ||
|  | 416c367778 | ||
|  | a20e90aa17 | ||
|  | d698eba1e7 | ||
|  | fe8e9414cf | ||
|  | ed216bea4d | ||
|  | 3350b56057 | ||
|  | 4d71f682b3 | ||
|  | 607cda779d | ||
|  | b61de07ca0 | ||
|  | 295ed76a1a | ||
|  | 7669f41e8e | ||
|  | 8da051789f | ||
|  | 30e0778ed2 | ||
|  | 7b1a256546 | ||
|  | cc4879fb76 | ||
|  | 7c54a45950 | ||
|  | 73513f8371 | ||
|  | dabf69abc7 | ||
|  | 8d3d5c068c | ||
|  | cb1d0441e9 | ||
|  | 8d827f98da | ||
|  | e5e46bf4ed | ||
|  | 9f32292473 | ||
|  | 7affeae480 | ||
|  | b0f7b71453 | ||
|  | c0c540dc09 | ||
|  | 7694ff1761 | ||
|  | 0d902671e5 | ||
|  | fb90a7889a | ||
|  | 48c73d6a34 | ||
|  | 12e462f383 | ||
|  | b7fe55b6be | ||
|  | a1270d6cc7 | ||
|  | f874c389bd | ||
|  | 8c5846c478 | ||
|  | dce807a329 | ||
|  | 7928e6d0cd | ||
|  | a98b726263 | ||
|  | 42ec4e4e98 | ||
|  | 635e3fb9a8 | ||
|  | 5f0b6fde92 | ||
|  | 04257afab7 | ||
|  | b673969a0f | ||
|  | c52c40f061 | ||
|  | abdb5cc6cb | ||
|  | 4a6817c64b | ||
|  | 328611c619 | ||
|  | f12c27aa7c | ||
|  | e22c62baba | ||
|  | 6b1158235e | ||
|  | efcaf64a43 | ||
|  | f120301bc8 | ||
|  | 4da63c9237 | ||
|  | 97294df84f | ||
|  | de42fc10b5 | ||
|  | e5c6b0d4ea | ||
|  | 7c7ca7ef2b | ||
|  | a813d32c53 | ||
|  | 2f18e20cb0 | ||
|  | 2ce2d63bda | ||
|  | 367e797d5f | ||
|  | 4fcf7bf2de | ||
|  | e1d51b51f2 | ||
|  | 40b4032ea0 | ||
|  | 756aa82aa9 | ||
|  | fe5a4a26f8 | ||
|  | 2171cb7f3d | ||
|  | f55a09862e | ||
|  | d0b21efd36 | ||
|  | daf4258472 | ||
|  | 619bc95b2b | ||
|  | 76c2fa6d9a | ||
|  | 77bf3ac6ce | ||
|  | 0d7761f097 | ||
|  | 6c08d0b20b | ||
|  | 148400ae0a | ||
|  | ac1657d86e | ||
|  | 332c314d53 | ||
|  | 5c8d386881 | ||
|  | 6f749c6414 | ||
|  | a6b6e1d101 | ||
|  | aa68cc2e63 | ||
|  | 5560ab28f2 | ||
|  | f624449ccb | ||
|  | 69de5bb828 | ||
|  | b54412e82e | ||
|  | dd19fc3f3e | ||
|  | dd436a689f | ||
|  | ee06778cc2 | ||
|  | b0c7fad81b | ||
|  | 0c28630948 | ||
|  | 198320be8a | ||
|  | da8451c637 | ||
|  | f54b8d8847 | ||
|  | f4fb758629 | ||
|  | b40fa61783 | ||
|  | 94cd9e5337 | ||
|  | 15c9fc4051 | ||
|  | 2b28607a4e | ||
|  | 683d5d5a48 | ||
|  | 4f92ef5fa9 | ||
|  | 44221fba49 | ||
|  | 63d7ed74f1 | ||
|  | 9012f2d6b1 | ||
|  | 09224e4b04 | ||
|  | 668e6fd610 | ||
|  | 62c3025a76 | ||
|  | 6e92c20edb | ||
|  | 60de577a5f | ||
|  | af58faafae | ||
|  | 5adf74e6ce | ||
|  | f4007a342c | ||
|  | 672234aaea | ||
|  | f19eebd3cc | ||
|  | 37fb5298a0 | ||
|  | 4280af4844 | ||
|  | d67e06037e | ||
|  | 4ce90a7eb4 | ||
|  | 4408c634b0 | ||
|  | df351511de | ||
|  | 3b85dc9618 | ||
|  | e511cfe2e4 | ||
|  | d0f8c1834d | ||
|  | d02bb28920 | ||
|  | 99861ac808 | ||
|  | 13ebd2c4e4 | ||
|  | 16c4807162 | ||
|  | 11aa4a6be0 | ||
|  | cf7f0f878a | ||
|  | 09c07f45ee | ||
|  | b5d205b78c | ||
|  | ad6bf936d5 | ||
|  | a6040c623b | ||
|  | 93a7af270f | ||
|  | 082fb166a2 | ||
|  | dccc075f2c | ||
|  | 5fdec48854 | ||
|  | fb51ebcba6 | ||
|  | 67e17def56 | ||
|  | 353bd3d06f | ||
|  | a7495f711b | ||
|  | e9d0a16a3b | ||
|  | 5072735866 | ||
|  | 1746ed6e1c | ||
|  | 664cd940c5 | ||
|  | 389536aff0 | ||
|  | f6c6c2b2c0 | ||
|  | 18d90ecd96 | ||
|  | 70fdfeb926 | ||
|  | 8c271cf40c | ||
|  | 665aeb34b2 | ||
|  | 98f304f8b0 | ||
|  | 7a5d2a3bd9 | ||
|  | f4d62d3342 | ||
|  | 54df7b0a3c | ||
|  | 9795a7c4a9 | ||
|  | 1557fda588 | ||
|  | 1e7f34c271 | ||
|  | d71e8ab7c9 | ||
|  | 3b4c8ba439 | ||
|  | 336dd1d5ba | ||
|  | a474e196ea | ||
|  | 101aefbfe8 | ||
|  | e04ebaa364 | ||
|  | bb4de11c51 | ||
|  | a20a5f1a44 | ||
|  | aab7043d45 | ||
|  | ee6d28b25e | ||
|  | ef504f3eba | ||
|  | 86407871e6 | ||
|  | 76bb2ef60c | ||
|  | beec65938e | ||
|  | 1c764052f7 | ||
|  | d501c0786f | ||
|  | 322c329c6f | ||
|  | 7c430e5c9d | ||
|  | 94b2b6393f | ||
|  | 4a1d20e8a3 | ||
|  | 8762e5160d | ||
|  | c33348e80c | ||
|  | 0c90f6afa2 | ||
|  | 115d42e0f0 | ||
|  | 6e43ab5897 | ||
|  | 8988c8f9af | ||
|  | aa21351d0d | ||
|  | 97109db82b | ||
|  | 8bb625adb7 | ||
|  | ea2d65f8bb | ||
|  | 1cf09d91bb | ||
|  | cf2b97b656 | ||
|  | 2e8cbd81b4 | ||
|  | b498c7bcbb | ||
|  | e78843bdca | ||
|  | 2eaf3136f9 | ||
|  | 6b6ab9fe6d | ||
|  | f35b9a4509 | ||
|  | 349ce004f8 | ||
|  | 1b63c95c4e | ||
|  | c80d53e7e5 | ||
|  | eb2028e0fa | ||
|  | 03689251c5 | ||
|  | 85c08312be | ||
|  | 16288d171c | ||
|  | 87044c54f4 | ||
|  | a4e8d3cb36 | ||
|  | dce6356d75 | ||
|  | c24e74efe3 | ||
|  | 60e247862a | ||
|  | c796cd2250 | ||
|  | c296a4a967 | ||
|  | 24192a3797 | ||
|  | f84d947115 | ||
|  | 9544dece07 | ||
|  | 6c4d7fd377 | ||
|  | 8d467ddd61 | ||
|  | db28ee1ff7 | ||
|  | e378cb410c | ||
|  | 144eee7fbf | ||
|  | 72e702a15a | ||
|  | 6b7be462b8 | ||
|  | 4329d393e6 | ||
|  | 4f52691f71 | ||
|  | c132d71684 | ||
|  | 8410f61c73 | ||
|  | cac76a182e | ||
|  | 5b0e93552c | ||
|  | 5eebd04d43 | ||
|  | 6f4aefffe7 | ||
|  | 377c219fd9 | ||
|  | da3d814c8b | ||
|  | 4461ecfed1 | ||
|  | bd676922c3 | ||
|  | 49356cadd4 | ||
|  | c02f222005 | ||
|  | d3977ce40e | ||
|  | 7283d7eb2f | ||
|  | 48252d284e | ||
|  | 807dc46ad0 | ||
|  | 0837ec9b70 | ||
|  | b380522df8 | ||
|  | c127d34d32 | ||
|  | bc0b97d5d8 | ||
|  | 431abe79f3 | ||
|  | 125470f110 | ||
|  | 4f669bdd66 | ||
|  | 8930236396 | ||
|  | b3c9a50ead | ||
|  | 4d0aee67be | ||
|  | b501c6d5bf | ||
|  | 7dcee38b21 | ||
|  | 903c63ac13 | ||
|  | a98c9f99d1 | ||
|  | 7f085df240 | ||
|  | b5ae141fb6 | ||
|  | 7eb866ffee | ||
|  | 61e59d74e0 | ||
|  | 5f50d2e230 | ||
|  | 3f1484480e | ||
|  | 2d3fc613ec | ||
|  | e2982185d6 | ||
|  | bdf4c6723f | ||
|  | 1d4f10bead | ||
|  | aac3e2d4fb | ||
|  | 87dd6badac | ||
|  | 1b6c7af3eb | ||
|  | 5c091a1871 | ||
|  | fb3839e096 | ||
|  | eef3ca0295 | ||
|  | c9dc0226fd | ||
|  | 1a7a3a4233 | ||
|  | d2e458f673 | ||
|  | e0f265db15 | ||
|  | 39a3cefc21 | ||
|  | 89db08eb93 | ||
|  | f40cf2cd8e | ||
|  | 50bb69b796 | ||
|  | a7d7c2b98b | ||
|  | 8dfc0d9dda | ||
|  | 0e6dce7093 | ||
|  | ddbf4470a1 | ||
|  | 829649e905 | ||
|  | bc063ad773 | ||
|  | ef38810425 | ||
|  | 5ccca8d708 | ||
|  | 89919dbe36 | ||
|  | ecd51a1428 | ||
|  | 4cb9eec257 | ||
|  | 78097b96c9 | ||
|  | 2af8589afd | ||
|  | cf1ace3a73 | ||
|  | efcc9d51d4 | ||
|  | 9b9f4be6a4 | ||
|  | a87c104172 | ||
|  | 028683666d | ||
|  | b2c59be8de | ||
|  | 2685e06528 | ||
|  | a99673122e | ||
|  | ba49012447 | ||
|  | fe8b090911 | ||
|  | c4a38de007 | ||
|  | 407eda0ba0 | ||
|  | 5b1dc0bfbd | ||
|  | 772b260b37 | ||
|  | bd75eddc8e | ||
|  | 00db3a0922 | ||
|  | 2bcc1b7fb4 | ||
|  | 433c848c8d | ||
|  | abdb3b9475 | ||
|  | 9761161163 | ||
|  | e5104021b1 | ||
|  | 9ef4f47ba0 | ||
|  | 3bbc88f89a | ||
|  | bfa61c8f67 | ||
|  | 3bdeb75cc2 | ||
|  | ca9eaf383a | ||
|  | 42a8d84a1f | ||
|  | 3fd330c2fb | ||
|  | 8f340afca1 | ||
|  | e28d9426b9 | ||
|  | b3078b75cd | ||
|  | 424b97994e | ||
|  | f30a52c2dc | ||
|  | 1db22f4a1b | ||
|  | 424e2a9439 | ||
|  | 2ee2e29262 | ||
|  | 7afd2dbd20 | ||
|  | cdb2446e32 | ||
|  | ac8c9215cd | ||
|  | dfca01e469 | ||
|  | ca1d980746 | ||
|  | 587d3f9012 | ||
|  | e30ab07439 | ||
|  | e6e026f420 | ||
|  | 2036518813 | ||
|  | 7536f5e83c | ||
|  | 229402594f | ||
|  | 97873ddb5d | ||
|  | dbf303d5d6 | ||
|  | 7346b3e326 | ||
|  | 93cf947e2a | ||
|  | c37ad5c8bf | ||
|  | 5a3e325742 | ||
|  | c5ec12cd56 | ||
|  | 3410541a2f | ||
|  | 80a68de91b | ||
|  | 1f39083555 | ||
|  | 5f8fb6c226 | ||
|  | d66dd01438 | ||
|  | 6d3bad1ae0 | ||
|  | 8b8b1427f6 | ||
|  | e2d971f20e | ||
|  | 9d17e8826b | ||
|  | 531c581cd5 | ||
|  | f790b9aa54 | ||
|  | 8f000423ed | ||
|  | 4990f6c22d | ||
|  | d447a50b73 | ||
|  | cbecfad4df | ||
|  | 770a7f11a7 | ||
|  | 27a65f8745 | ||
|  | 5cd06c03f0 | ||
|  | 43e5092c46 | ||
|  | a239e3fba6 | ||
|  | 743d772a80 | ||
|  | 1f734630b9 | ||
|  | 355fe6195e | ||
|  | d22bd5b42d | ||
|  | 5327ce543b | ||
|  | 3747eb59ea | ||
|  | 2b00ab3432 | ||
|  | a6cdd701e2 | ||
|  | c8984e6a6a | ||
|  | 9179aa52cf | ||
|  | 2042fdf3bd | ||
|  | d1c3372dc4 | ||
|  | 3884a68889 | ||
|  | 0ec84ec597 | ||
|  | 6a9d21e9aa | ||
|  | a829d44b51 | ||
|  | 554e3e9e6e | ||
|  | 904b3b5b0b | ||
|  | 14bdc0e57a | ||
|  | 02bdc1dcb9 | ||
|  | 7be2db6e86 | ||
|  | b586ae2f25 | ||
|  | d0ed814669 | ||
|  | 8492a702b2 | ||
|  | 0048156379 | ||
|  | cb3328dca3 | ||
|  | e7b7ae94b0 | ||
|  | 17ce295c30 | ||
|  | 4e9166759d | ||
|  | d5e3bb1b6d | ||
|  | 7e4e5ec6e4 | ||
|  | f2656e62dc | ||
|  | 83de97e547 | ||
|  | b552efe770 | ||
|  | 1663c7c8e7 | ||
|  | 1a6bef1a7e | ||
|  | ff31e75ccc | ||
|  | c87a37f804 | ||
|  | 76ead096aa | ||
|  | 668ff71470 | ||
|  | 538d5e8be4 | ||
|  | b2b142a037 | ||
|  | 3ebed4ff40 | ||
|  | a2cd69b654 | ||
|  | cfc14671ed | ||
|  | ed4b2f74ff | ||
|  | dd53be7a1b | ||
|  | c83d7916c9 | ||
|  | 0865962f8d | ||
|  | 9691085bc2 | ||
|  | b243d1c599 | ||
|  | db6e404bda | ||
|  | 6f63e24dbb | ||
|  | 0082fe8173 | ||
|  | 06d37b2a94 | ||
|  | 48f11900d3 | ||
|  | 230cd28ac9 | ||
|  | 86261f2b0a | ||
|  | 30ad00fa65 | ||
|  | 33a1499bdd | ||
|  | 211fa18ac2 | ||
|  | 4c5250e850 | ||
|  | 788024685f | ||
|  | b5f07d2995 | ||
|  | 8d7af21ff3 | ||
|  | dce9278193 | ||
|  | c6e783e7c3 | ||
|  | c8fa059064 | ||
|  | 29efac3e5e | ||
|  | 027d313df5 | ||
|  | ea78808e74 | ||
|  | 6f6f999129 | ||
|  | b16ebd529b | ||
|  | 25deecd405 | ||
|  | 2471f893e7 | ||
|  | 17480abe85 | ||
|  | bfde17b4d7 | ||
|  | 76263a9610 | ||
|  | 855468e776 | ||
|  | beceea9421 | ||
|  | dabc139fab | ||
|  | 41aea2e336 | ||
|  | f929346c18 | ||
|  | e699662b1e | ||
|  | 90057318c8 | ||
|  | 6f2eaf3009 | ||
|  | e8fc16dc09 | ||
|  | 0f1911ba68 | ||
|  | 94699fbe00 | ||
|  | a380317e2c | ||
|  | 64bcdd4398 | ||
|  | 56e0580aa5 | ||
|  | 7f0c9c239e | ||
|  | e0a1592e6e | ||
|  | 3d784a14f9 | ||
|  | 47a9b086ea | ||
|  | e70c8a7b46 | ||
|  | 673351d821 | ||
|  | 4b966f1f82 | ||
|  | 93626de01c | ||
|  | 7847b7685d | ||
|  | 255e88fbf6 | ||
|  | 685c6dc00c | ||
|  | 8e18d37b3d | ||
|  | b4c7b90c9e | ||
|  | b55be9fdea | ||
|  | 401b3afa3b | ||
|  | 7fa3537015 | ||
|  | 149ed91afb | ||
|  | 887826ee68 | ||
|  | 7357d5eae2 | ||
|  | e4e2a188c5 | ||
|  | e40e3af760 | ||
|  | 24a2788081 | ||
|  | 1388266102 | ||
|  | 43af0b051f | ||
|  | 6e8138e19b | ||
|  | fb8edd86d5 | ||
|  | 34be181706 | ||
|  | fcc1109e76 | ||
|  | 2b828765e3 | ||
|  | 25f4c23ab2 | ||
|  | be90b20a5d | ||
|  | 232c113dae | ||
|  | 605a9b2817 | ||
|  | d044c0f4cc | ||
|  | 1959e1fd44 | ||
|  | 6712423dd1 | ||
|  | 3689990bd5 | ||
|  | 81a1f618f9 | ||
|  | b77bb690de | ||
|  | f843f260ee | ||
|  | 770b3739e0 | ||
|  | 261e7c1744 | ||
|  | 10acbb8d92 | ||
|  | a917115a85 | ||
|  | b8ed6f1588 | ||
|  | 3ed57e01a6 | ||
|  | cb7c5a8ca1 | ||
|  | 07eb9c5970 | ||
|  | 306e5081d9 | ||
|  | 259c7adc81 | ||
|  | af9762cf32 | ||
|  | 17554202f6 | ||
|  | 0d9cf697fa | ||
|  | df0dd2f5e6 | ||
|  | 38508f9a9c | ||
|  | b113972bcf | ||
|  | 72e67bf4e9 | ||
|  | a20a6636b4 | ||
|  | da8aa2d8e4 | ||
|  | 602a2ea541 | ||
|  | fd24b1898e | ||
|  | 89150e1164 | ||
|  | e1831c4c60 | ||
|  | 4ec90c5c0d | ||
|  | a8c73f7baf | ||
|  | 6fed76a687 | ||
|  | 84de444325 | ||
|  | 0fbd87ca87 | ||
|  | 99797502eb | ||
|  | 16bd0b9ca8 | ||
|  | 5fdfa963f4 | ||
|  | 1d86e71331 | ||
|  | 9e3f549341 | ||
|  | 2895ad21f3 | ||
|  | 5731ae7f47 | ||
|  | 51f7d9a07f | ||
|  | 6be390c795 | ||
|  | 0f32de4aa2 | ||
|  | 5d01452648 | ||
|  | 51b0508512 | ||
|  | 4c5e7a238d | ||
|  | f327b7b499 | ||
|  | 306e86c9c6 | ||
|  | 9024f1b444 | ||
|  | fc26e8c194 | ||
|  | ffd8e5667c | ||
|  | 9299c3abc7 | ||
|  | 88ebac942e | ||
|  | 63a07fe6cf | ||
|  | c2d440a914 | ||
|  | 2b5c7f9e91 | ||
|  | 91e63dea47 | ||
|  | cd164de776 | ||
|  | c0ef5ce512 | ||
|  | 7c852fbf33 | ||
|  | 28500989bc | ||
|  | 75c99a0491 | ||
|  | 8b4ba3cb67 | ||
|  | 3ef2971c3f | ||
|  | a5aa8c6006 | ||
|  | 022d14abe1 | ||
|  | 1800b0b69c | ||
|  | c39a550b00 | ||
|  | 092aa8fa6d | ||
|  | f75f73f3d2 | ||
|  | e3627e9cba | ||
|  | d5f4934acf | ||
|  | 693bd7e110 | ||
|  | 4d8dcdc623 | ||
|  | 8e97af8dc3 | ||
|  | 4dc448056c | ||
|  | 68c349bbfa | ||
|  | 75aedc8e94 | ||
|  | 8b08f89d2c | ||
|  | 889b38f75a | ||
|  | a17ac23457 | ||
|  | 6fdd48509e | ||
|  | 62800116d3 | ||
|  | 1bccbf061b | ||
|  | 093658836e | ||
|  | f49800e56a | ||
|  | e478dbeb85 | ||
|  | 51486b18fa | ||
|  | 48d98dcf45 | ||
|  | 2c7cfd1c68 | ||
|  | 7a4b4c941c | ||
|  | 608ccb0ca1 | ||
|  | 3f6ea04048 | ||
|  | 74c5ec70a9 | ||
|  | c8bf8e896a | ||
|  | 09cc1161c9 | ||
|  | 8ab33db51a | ||
|  | cc4258bf9d | ||
|  | 0ee5d3d83f | ||
|  | c39aa5e857 | ||
|  | 39aae4167e | ||
|  | 9db9143366 | ||
|  | 06df6017df | ||
|  | 49814b92fe | ||
|  | 260b5d6b0d | ||
|  | 4360ca14c1 | ||
|  | c7d336f958 | ||
|  | f6436663eb | ||
|  | 84d7c65039 | ||
|  | 4245096be4 | ||
|  | c9b2a07bc7 | ||
|  | e69d4cba88 | ||
|  | 96962dd21f | ||
|  | 36d48224b5 | ||
|  | 15b5433f1a | ||
|  | 53779d6ceb | ||
|  | e7e268b3bd | ||
|  | ca2f76fe1f | ||
|  | 4d44ab9628 | ||
|  | dd62051e6c | ||
|  | fdb1701d1b | ||
|  | 80b35575df | ||
|  | 69cf05df9a | ||
|  | 69a1817c3f | ||
|  | a918dcd5a4 | ||
|  | adc9a65ae3 | ||
|  | 1e779f7135 | ||
|  | fe68e9e243 | ||
|  | 890d02638b | ||
|  | e9792b446f | ||
|  | 4012599264 | ||
|  | 429b1d8574 | ||
|  | a34876d700 | ||
|  | 68ecf78f0e | ||
|  | 38344b342d | ||
|  | 346ff96de2 | ||
|  | 31614bebc4 | ||
|  | be888b59a6 | ||
|  | 6069df6cbd | ||
|  | 5e7b6e4860 | ||
|  | ea6fa6e889 | ||
|  | 3e914256ce | ||
|  | 85ce16b34f | ||
|  | d306c8fd50 | ||
|  | 8d7eccad5d | ||
|  | d18edd6f77 | ||
|  | cad3704efd | ||
|  | 9a4b455c3f | ||
|  | 01c8798e4e | ||
|  | 61744fba11 | ||
|  | 0034bef6b9 | ||
|  | 63c3ed3931 | ||
|  | 8a5db8a3ee | ||
|  | adc2b62c22 | ||
|  | 1f2fe08c33 | ||
|  | 77b1933833 | ||
|  | c4df78b4b9 | ||
|  | c1dc783512 | ||
|  | 518a37e776 | ||
|  | b143101f82 | ||
|  | 2be6f4d153 | ||
|  | ac612734c8 | ||
|  | ffe69c67fc | ||
|  | b3057a0ec3 | ||
|  | 563f059e73 | ||
|  | 6bbe7262ef | ||
|  | 55a1a81010 | ||
|  | 97ec764db7 | ||
|  | f6df556eb0 | ||
|  | 5cd9396dae | ||
|  | 886a6bdbe0 | ||
|  | ab60e702d2 | ||
|  | 17141b3589 | ||
|  | 8f23243cb8 | ||
|  | c2345c6e9a | ||
|  | 2617de2cdd | ||
|  | 9cf6827ccc | ||
|  | 681892148e | ||
|  | 558452a143 | ||
|  | 5a173fa968 | ||
|  | 72397ef90c | ||
|  | 79ad4b4544 | ||
|  | 49f3713c4f | ||
|  | 4b5c3ccf58 | ||
|  | 21dec70971 | ||
|  | 0f2b774ea1 | ||
|  | e929caf15a | ||
|  | 8d848c3d60 | ||
|  | b8b0c8f3e5 | ||
|  | 15e78da7eb | ||
|  | d80700810f | ||
|  | c1de6abf23 | ||
|  | 11f04a453e | ||
|  | 01b916eaa0 | ||
|  | 62c03b3318 | ||
|  | 65679af61d | ||
|  | 821ad31cf6 | ||
|  | ea750ad813 | ||
|  | 3d7633f4a6 | ||
|  | d356ef1c5b | ||
|  | fce762febf | ||
|  | 535280c162 | ||
|  | bb8a193244 | ||
|  | e6bdfa1d29 | ||
|  | d1d2611665 | ||
|  | 8389b46b5c | ||
|  | b9f826554c | ||
|  | 0750235712 | ||
|  | ee0e014617 | ||
|  | 2e20394af4 | ||
|  | 6ab991ebf4 | ||
|  | ef8894ef26 | ||
|  | 8b4efa1760 | ||
|  | b0b8b75258 | ||
|  | 2e19e45aa4 | ||
|  | e1d097ea20 | ||
|  | ed12366d52 | ||
|  | 4919b638f9 | ||
|  | 49563e638b | ||
|  | 07d0eb9ae6 | ||
|  | 336135c392 | ||
|  | d2b38e6ac4 | ||
|  | 883f90dded | ||
|  | 58e82743f8 | ||
|  | 51a0994d2d | ||
|  | da20db862d | ||
|  | d6c9f51082 | ||
|  | 08d7bb0d08 | ||
|  | 1bcb3d8cc2 | ||
|  | c17de070fb | ||
|  | b893374dc1 | ||
|  | fe532ed4f2 | ||
|  | 7baa752a9d | ||
|  | 6377a19b12 | ||
|  | ca7ea68a6a | ||
|  | a45f285a5c | ||
|  | fa2c57f7cb | ||
|  | 0779c6a139 | ||
|  | 2916f540c1 | ||
|  | 7932e317c8 | ||
|  | fd26cf265d | ||
|  | 3e76c25887 | ||
|  | a0e2f47679 | ||
|  | d70add10ab | ||
|  | 119d0134e0 | ||
|  | 2e085fa253 | ||
|  | f8f7edd124 | ||
|  | 79ecff7b42 | ||
|  | 0f2c4fb5f4 | ||
|  | ec1952157b | ||
|  | cd38359458 | ||
|  | 8a86777db8 | ||
|  | e7033071b9 | ||
|  | f99a473436 | ||
|  | c4b7e8f288 | ||
|  | f346251719 | ||
|  | 4c3cf87f62 | ||
|  | cb417b8077 | ||
|  | 076d6abfe4 | ||
|  | 82308c9a53 | ||
|  | 5d35079809 | ||
|  | 50e24f461c | ||
|  | 37886892c8 | ||
|  | 72ffa91fe0 | ||
|  | 9908137638 | ||
|  | f3ecc040c8 | ||
|  | e271378a97 | ||
|  | 5d050ae3ac | ||
|  | 615ceab597 | ||
|  | f1b085fa36 | ||
|  | bd4c822670 | ||
|  | 03d5a95bde | ||
|  | e2ec64947a | ||
|  | dabd9e2208 | ||
|  | 4c060a78cc | ||
|  | cfaf47c8a2 | ||
|  | 87da7520de | ||
|  | 4a68d29ce2 | ||
|  | 0ca2149408 | ||
|  | 0cfaab02c0 | ||
|  | 2d54065082 | ||
|  | 3cfbe7cf6d | ||
|  | e2d8a95c91 | ||
|  | 3419f9aeb9 | ||
|  | ebded2cbc0 | ||
|  | fb617044e0 | ||
|  | 5a0b5470e7 | ||
|  | 6b4144ad10 | ||
|  | 8f16ff9c49 | ||
|  | ac6b11037d | ||
|  | 848e45c22c | ||
|  | 2c0bf335ba | ||
|  | aef24dd74b | ||
|  | c2c6aee18a | ||
|  | 6451b47621 | ||
|  | 2b2cfdfb32 | ||
|  | 5f4d440493 | ||
|  | 5f0451affe | ||
|  | 156f6b8d3c | ||
|  | f0ee2890b2 | ||
|  | 16c283c91a | ||
|  | db13dbdf46 | ||
|  | 06905cb14a | ||
|  | 6ea9c4dd3f | ||
|  | c5c8382742 | ||
|  | 115ddc6a4a | ||
|  | 54ca0ce34f | ||
|  | f19c497621 | ||
|  | 0561a20c06 | ||
|  | 162490dadf | ||
|  | 30087794ba | ||
|  | 9ebe3c38b2 | ||
|  | 7155f0d50d | ||
|  | 75e05ca142 | ||
|  | 5d4423910d | ||
|  | 0de1ff8634 | ||
|  | e5fb1ffeb7 | ||
|  | 8c53318dac | ||
|  | 0d6f259adc | ||
|  | 85ab0e6e70 | ||
|  | a18294d417 | ||
|  | fecd0ca391 | ||
|  | 97bd92c76f | ||
|  | 49b89c30d8 | ||
|  | 8228a8e3f7 | ||
|  | 78be3df99a | ||
|  | 2f0db9a974 | ||
|  | 227fab3867 | ||
|  | 9537449b07 | ||
|  | 246b245959 | ||
|  | a433e469cc | ||
|  | 04958c6951 | ||
|  | b54c956c5e | ||
|  | 8735263930 | ||
|  | a79d6aa669 | ||
|  | 7efafa5a2c | ||
|  | 0b436563bd | ||
|  | 5d379dc3e3 | ||
|  | 8c60774c6a | ||
|  | 9b2423aaba | ||
|  | fc8c24e987 | ||
|  | d7bd69714d | ||
|  | 099bbb8be7 | ||
|  | c29a69a60d | ||
|  | 69e4f35d9a | ||
|  | ff40467207 | ||
|  | 190c6c661f | ||
|  | e633799c14 | ||
|  | f7c6c562a5 | ||
|  | bc6e9d5042 | ||
|  | a0b1d54012 | ||
|  | 60b5286f8c | ||
|  | aa3ea17a8f | ||
|  | 698621f127 | ||
|  | 906f4fe8f7 | ||
|  | ddf199566c | ||
|  | a47d770e71 | ||
|  | 057498ed01 | ||
|  | fa562dc916 | ||
|  | 0be895febb | ||
|  | 11a0078966 | ||
|  | 92f8e5cd3f | ||
|  | 5b3762be08 | ||
|  | 3b01488c8d | ||
|  | 2f65572247 | ||
|  | e42ddfc3d6 | ||
|  | d63636243c | ||
|  | a0b9c0d007 | ||
|  | 1f7a4174ba | ||
|  | 761c58e040 | ||
|  | 01c3d3905c | ||
|  | c815a732ef | ||
|  | 5d91c7e15c | ||
|  | c39d21c178 | ||
|  | b6498cdcbc | ||
|  | a09dfa3ce1 | ||
|  | d3ae88f108 | ||
|  | 1fad7e5a1c | ||
|  | 19546ab518 | ||
|  | e6e9a86919 | ||
|  | c6dd1dccc3 | ||
|  | 993caf5058 | ||
|  | 450471d30a | ||
|  | 7eeecd23ac | ||
|  | 21c94141ba | ||
|  | bc2cba5aa4 | ||
|  | 5e49354bf2 | ||
|  | 55334b2062 | ||
|  | 74dc5b1c58 | ||
|  | ac11323fdd | ||
|  | 8c2e99432d | ||
|  | aa26927d61 | ||
|  | 22ee8700ca | ||
|  | df55c24cb5 | ||
|  | 99ddd7f9cb | ||
|  | 82b2a102ed | ||
|  | c7df82e695 | ||
|  | 638960284e | ||
|  | 8e9b8a0953 | ||
|  | 3f044c48fa | ||
|  | 37d8e32e0b | ||
|  | 46ce807624 | ||
|  | e6a88f3531 | ||
|  | 95d86d84b4 | ||
|  | 70fa42aee0 | ||
|  | ba99fbe390 | ||
|  | 6a55772cda | ||
|  | 6dcb51a4bd | ||
|  | c875819a2e | ||
|  | 6d4cf0d892 | ||
|  | 78a9d20691 | ||
|  | 7c2409b5a7 | ||
|  | 0335f6fba9 | ||
|  | 2c7b7cd6ca | ||
|  | 5632952665 | ||
|  | 7eeac63139 | ||
|  | 1b54f4d32a | ||
|  | e8e9dd9400 | ||
|  | b722748ec3 | ||
|  | 609b2630d7 | ||
|  | 5bdf8a5ea3 | ||
|  | 7a2592b2fa | ||
|  | 546bebc860 | ||
|  | ad51f4f2a5 | ||
|  | 94a6f8426b | ||
|  | 32f7fb8bff | ||
|  | a777c3553c | ||
|  | 51650c1412 | ||
|  | 157580c232 | ||
|  | 05f052b092 | ||
|  | 1431ac5751 | ||
|  | a9deeb321b | ||
|  | ec86149b1e | ||
|  | 31f92001e2 | ||
|  | d69977c229 | ||
|  | 44e06a1a1e | ||
|  | f9689d1562 | ||
|  | 4cb1ae4626 | ||
|  | f04813fa02 | ||
|  | 742029d8a4 | ||
|  | f74526a36e | ||
|  | 61e1836472 | ||
|  | 8d8e509fe6 | ||
|  | 147e79ea07 | ||
|  | 5eae95ee46 | ||
|  | 9e26f0b058 | ||
|  | 8cc3c4a6b7 | ||
|  | 1d8bdd4384 | ||
|  | 5acd43efaf | ||
|  | 7033b996c6 | ||
|  | 0c76a8ac89 | ||
|  | f10516deb7 | ||
|  | d4311f9cf5 | ||
|  | 6a50a6fd5a | ||
|  | 29473ef356 | ||
|  | 1f1ecb15f6 | ||
|  | 38d655636d | ||
|  | 9ab5cbf235 | ||
|  | fdf14cd101 | ||
|  | f63873cc73 | ||
|  | c2938ff138 | ||
|  | ab2c98d931 | ||
|  | 0ae8cd9a9d | ||
|  | f3aefe282c | ||
|  | a80cca95a2 | ||
|  | c52f4b043d | ||
|  | 253060b4f3 | ||
|  | 36966da701 | ||
|  | bb7c4aaf7e | ||
|  | bd4846aa9c | ||
|  | c68ebaa2ca | ||
|  | 538424b01c | ||
|  | 48e7a87741 | ||
|  | 74ace58ae1 | ||
|  | 913d8737cc | ||
|  | b98f5ed8b1 | ||
|  | e4bb506ace | ||
|  | 0f0ba099c9 | ||
|  | f400292be7 | ||
|  | efc6560d83 | ||
|  | 4055654e9b | ||
|  | 56488d435f | ||
|  | f586950528 | ||
|  | a302731cd1 | ||
|  | 00728e711c | ||
|  | ef753838e7 | ||
|  | acb79d6f73 | ||
|  | 157c796294 | ||
|  | 0861c59bec | ||
|  | e4a7375d34 | ||
|  | 6bbac65f7e | ||
|  | 845f1a7377 | ||
|  | 9c8e518423 | ||
|  | bd3b787fd5 | ||
|  | 27e4a8a227 | ||
|  | cf2d7497e4 | ||
|  | df41cd925e | ||
|  | e46de74328 | ||
|  | feeb7f81a6 | ||
|  | 2beb5236d0 | ||
|  | f062ee80c8 | ||
|  | a7bb768e98 | ||
|  | 07be89d6e9 | ||
|  | d81c4e6d1a | ||
|  | 870755e90d | ||
|  | bd3c8c3cde | ||
|  | 278b3180c3 | ||
|  | bb2686a08f | ||
|  | 202783ca7d | ||
|  | 308904110a | ||
|  | 60b4095c75 | ||
|  | d04b4fa2cc | ||
|  | 2d449f63e0 | ||
|  | 1ec4e03738 | ||
|  | 9cd47dd2aa | ||
|  | 015cd7a3d0 | ||
|  | 7ff6e6b66f | ||
|  | e92b01c528 | ||
|  | bb33128552 | ||
|  | 86add29838 | ||
|  | 70712a0f62 | ||
|  | 4db937b571 | ||
|  | ad6f41c77a | ||
|  | e6040e55f5 | ||
|  | dad0e75121 | ||
|  | c159e316be | ||
|  | b4ac3d4470 | ||
|  | 43d22d7a2f | ||
|  | d62f7e2082 | ||
|  | cfe2f1a1e6 | ||
|  | 6f6ebb8025 | ||
|  | 7732e2307e | ||
|  | 8c733abef3 | ||
|  | 4809476c19 | ||
|  | d727761e5d | ||
|  | 4d79c2a6d2 | ||
|  | 8627256e74 | ||
|  | ed0c7d9c49 | ||
|  | fb4717d5f3 | ||
|  | 09b489a614 | ||
|  | 402f7011d4 | ||
|  | 838dd8c19f | ||
|  | 91cafd1752 | ||
|  | eea60b6baa | ||
|  | baf8d63cb4 | ||
|  | 967e4208da | ||
|  | ba3a579d07 | ||
|  | 1d53077fc7 | ||
|  | 4b480ece13 | ||
|  | 7d2b7cd7f1 | ||
|  | 73b4df4e18 | ||
|  | a23a9228da | ||
|  | 37aa902cef | ||
|  | bafb583666 | ||
|  | aabebb2185 | ||
|  | f611ef0edd | ||
|  | d8f69700e6 | ||
|  | c8ae97fd38 | ||
|  | d50b6a34bc | ||
|  | 853be929bc | ||
|  | 3bb04142f3 | ||
|  | d53fbb9d7f | ||
|  | a1911a9608 | ||
|  | ff2e2d5026 | ||
|  | a953d3ad89 | ||
|  | 9ce444b91a | ||
|  | ae8be89767 | ||
|  | 5774d100c1 | ||
|  | dbe720f0f1 | ||
|  | 5afc8f2b12 | ||
|  | c7e008f57a | ||
|  | 14b7152bf0 | ||
|  | 3ef6bf2118 | ||
|  | f0ab2721a5 | ||
|  | 2721c2017c | ||
|  | a7c158f0e1 | ||
|  | 7ff9193cf5 | ||
|  | 5ce4a2d05c | ||
|  | 031451abab | ||
|  | 8d75aba7eb | ||
|  | 027093a5a5 | ||
|  | bdc0e3bfcf | ||
|  | b2a57ca1f3 | ||
|  | 6ef0e6791b | ||
|  | 9374d6b3b9 | ||
|  | f173ff02e3 | ||
|  | ba2046491a | ||
|  | 083b471bcf | ||
|  | bf73127e0b | ||
|  | 333b785061 | ||
|  | 79bf19c897 | ||
|  | 0c0ecc1cdc | ||
|  | bacd58ed7b | ||
|  | 689f120410 | ||
|  | 2303301d38 | ||
|  | f323df466d | ||
|  | b1f1a5b757 | ||
|  | 0d262561d1 | ||
|  | 12c713b187 | ||
|  | b1836587f2 | ||
|  | 04d8b5d483 | ||
|  | 461ebf6d88 | ||
|  | 41eb4f1c70 | ||
|  | 31a8e3e39a | ||
|  | 139f280f35 | ||
|  | 17ad5153b8 | ||
|  | bb14ec70bd | ||
|  | e8e36bd9d5 | ||
|  | f9b1106df2 | ||
|  | df600d6f3c | ||
|  | 157e76e829 | ||
|  | dbc3b85cd0 | ||
|  | 11691019a0 | ||
|  | 3192307d59 | ||
|  | ba8c9295ac | ||
|  | d5436fb28b | ||
|  | 886cc83ad9 | ||
|  | 9e012a6b54 | ||
|  | 5eda08e9b8 | ||
|  | ec6e46e2cb | ||
|  | 56fe023a12 | ||
|  | aa705dd691 | ||
|  | aa6fea7f21 | ||
|  | e31c85aace | ||
|  | 1c3e4124f8 | ||
|  | 586ba31120 | ||
|  | c1757372d3 | ||
|  | 7451449dd6 | ||
|  | 5b2b29043c | ||
|  | 2758664226 | ||
|  | bb3f28ffa7 | ||
|  | 6ceb2af4a7 | ||
|  | d5b649bf1c | ||
|  | 81f23cc732 | ||
|  | b59276ff1c | ||
|  | 2e95832812 | ||
|  | 01f2b3cd20 | ||
|  | 2240bf9430 | ||
|  | db036edccd | ||
|  | 1fbf5b84a2 | ||
|  | 08e1f626c1 | ||
|  | c0d08f5e3e | ||
|  | eac20d61df | ||
|  | dec3f0798a | ||
|  | bddb4cc33c | ||
|  | 62ded580ce | ||
|  | 51227241b7 | ||
|  | 9cf4e730e7 | ||
|  | e9c63f3988 | ||
|  | 2c47691cf1 | ||
|  | 599b699ac9 | ||
|  | a5beeb4f04 | ||
|  | 446d73fcf5 | ||
|  | e299775d67 | ||
|  | 2c18750537 | ||
|  | f317e50136 | ||
|  | 1d84bda7ca | ||
|  | ae7c947ba5 | ||
|  | 6d07729c55 | ||
|  | 1d7bf200a8 | ||
|  | 6bc59f8b33 | ||
|  | b2cf03fa5c | ||
|  | 36e273714d | ||
|  | 6be77b7fb9 | ||
|  | 6bcf45f136 | ||
|  | 8bca8236db | ||
|  | 67a0b4b4b1 | ||
|  | a7200a292b | ||
|  | fb5aa4c9c1 | ||
|  | 3f5772c62a | ||
|  | e76836b948 | ||
|  | 2d946d7ee7 | ||
|  | 10ca35dccd | ||
|  | bfdd1997f6 | ||
|  | 9420308667 | ||
|  | 83e09acc9f | ||
|  | d6d795e286 | ||
|  | c09febfffc | ||
|  | 5b3bba8f6e | ||
|  | 085593b9e5 | ||
|  | e2a5d4f83e | ||
|  | e3671cbb04 | ||
|  | a525d02cc5 | ||
|  | 3c8c5ebb96 | ||
|  | 1cc1a4e6e2 | ||
|  | 3f0af3fe09 | ||
|  | e2bac47a0a | ||
|  | bc26d9f0de | ||
|  | 5c4692a0df | ||
|  | 0ba28bbc8b | ||
|  | 550184275a | ||
|  | c376083ecb | ||
|  | 1db5fcf200 | ||
|  | 16b2555ab3 | ||
|  | 9227d32d57 | ||
|  | c37b040217 | ||
|  | 5a1d2aa4b6 | ||
|  | 4a3b1f3847 | ||
|  | d9a5258f40 | ||
|  | 190ebbed27 | ||
|  | a0872c9e31 | ||
|  | 68cc826519 | ||
|  | f5b306e7ff | ||
|  | 7a1feb3c51 | ||
|  | e691168cdc | ||
|  | 4eda1e1bd4 | ||
|  | 1e8df9f245 | ||
|  | b72937e8fb | ||
|  | df11e67bb4 | ||
|  | b7d20496f3 | ||
|  | 67847c3117 | ||
|  | a2a0c80acb | ||
|  | b3fd06fb45 | ||
|  | c5db8d903c | ||
|  | 8fcd242494 | ||
|  | ebd9af900e | ||
|  | b02381c2d5 | ||
|  | dce65ab9c2 | ||
|  | 97295f270b | ||
|  | 8e64bc8785 | ||
|  | 9b199ea756 | ||
|  | ec3b913ee4 | ||
|  | c210ab31d9 | ||
|  | 6c1fa91c70 | ||
|  | 04bab185f6 | ||
|  | 2213b4cf37 | ||
|  | 1d770e5636 | ||
|  | b7e15e0a2c | ||
|  | 9c651ae913 | ||
|  | a1bbaec71f | ||
|  | 3b3ca89483 | ||
|  | b4e3bca6fa | ||
|  | e09d5cb4ec | ||
|  | cae353b9f6 | ||
|  | edb5b3d711 | ||
|  | 667a0c41ed | ||
|  | 9daae9c705 | ||
|  | 2975acdc82 | ||
|  | 76dcbe3429 | ||
|  | d8e2d464ad | ||
|  | 5f8bcb0c26 | ||
|  | 7ef8d6fa10 | ||
|  | 5924a40222 | ||
|  | 05968eb232 | ||
|  | 36dcfbfe2d | ||
|  | 95ce4f5c1e | ||
|  | f258f20b04 | ||
|  | 7e2ad827aa | ||
|  | e6ce61fdf0 | ||
|  | 3df588047d | ||
|  | ac0e5cbb29 | ||
|  | 5ab584bc6a | ||
|  | a2e03e3bd0 | ||
|  | f0589b310f | ||
|  | 8519b0d353 | ||
|  | 21b8b2deb5 | ||
|  | 6b82a77e36 | ||
|  | 1954a49f37 | ||
|  | 0e3d1e1503 | ||
|  | ebd77f314d | ||
|  | 749d833f65 | ||
|  | 0373cd6f97 | ||
|  | 1f3fc8a366 | ||
|  | 89c3930b28 | ||
|  | 29e1e9eef2 | ||
|  | de3aeb9732 | ||
|  | 85aa1a444a | ||
|  | 702876ae7f | ||
|  | 7109910f46 | ||
|  | 8168d2fdc1 | ||
|  | edbcd01fbc | ||
|  | c99266e961 | ||
|  | f804053736 | ||
|  | 2641832304 | ||
|  | 21f6f81914 | ||
|  | ccd919aba3 | ||
|  | 2387010556 | ||
|  | f35d574759 | ||
|  | 3be74bb275 | ||
|  | b1be062437 | ||
|  | 2d0d320d05 | ||
|  | 1de5111ab5 | ||
|  | 3d530e4747 | ||
|  | 0ef1b7b683 | ||
|  | 66485e81b4 | ||
|  | e74e7cf734 | ||
|  | 03ce6a1cc4 | ||
|  | a19b93c966 | ||
|  | f7fd1f2a63 | ||
|  | 88b71d23db | ||
|  | 762ef12eb6 | ||
|  | 6845068b82 | ||
|  | 5c0b18efe4 | ||
|  | 4b93d040b3 | ||
|  | ff61cc971e | ||
|  | 46db91ce73 | ||
|  | 5921909ef5 | ||
|  | 1537861c61 | ||
|  | 1b93551572 | ||
|  | 197a5fbcf4 | ||
|  | ff32529345 | ||
|  | a179c3b399 | ||
|  | a820585f56 | ||
|  | bfb12f415c | ||
|  | a731b43b52 | 
| @@ -1,3 +1,5 @@ | ||||
| dist/ | ||||
| !dist/traefik | ||||
| !dist/**/traefik | ||||
| site/ | ||||
| vendor/ | ||||
| .idea/ | ||||
|   | ||||
							
								
								
									
										3
									
								
								.gitattributes
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										3
									
								
								.gitattributes
									
									
									
									
										vendored
									
									
								
							| @@ -1,2 +1 @@ | ||||
| vendor/github.com/xenolf/lego/providers/dns/cloudxns/cloudxns.go eol=crlf | ||||
|  | ||||
| # vendor/github.com/go-acme/lego/providers/dns/cloudxns/cloudxns.go eol=crlf | ||||
|   | ||||
							
								
								
									
										24
									
								
								.github/CODEOWNERS
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										24
									
								
								.github/CODEOWNERS
									
									
									
									
										vendored
									
									
								
							| @@ -1,24 +0,0 @@ | ||||
| provider/kubernetes/**  @containous/kubernetes | ||||
| provider/rancher/**     @containous/rancher | ||||
| provider/marathon/**    @containous/marathon | ||||
| provider/docker/**      @containous/docker | ||||
|  | ||||
| docs/user-guide/kubernetes.md       @containous/kubernetes | ||||
| docs/user-guide/marathon.md         @containous/marathon | ||||
| docs/user-guide/swarm.md            @containous/docker | ||||
| docs/user-guide/swarm-mode.md       @containous/docker | ||||
|  | ||||
| docs/configuration/backends/docker.md       @containous/docker | ||||
| docs/configuration/backends/kubernetes.md   @containous/kubernetes | ||||
| docs/configuration/backends/marathon.md     @containous/marathon | ||||
| docs/configuration/backends/rancher.md      @containous/rancher | ||||
|  | ||||
| examples/k8s/                   @containous/kubernetes | ||||
| examples/compose-k8s.yaml       @containous/kubernetes | ||||
| examples/k8s.namespace.yaml     @containous/kubernetes | ||||
| examples/compose-rancher.yml    @containous/rancher | ||||
| examples/compose-marathon.yml   @containous/marathon | ||||
|  | ||||
| vendor/github.com/gambol99/go-marathon  @containous/marathon | ||||
| vendor/github.com/rancher               @containous/rancher | ||||
| vendor/k8s.io/                          @containous/kubernetes | ||||
							
								
								
									
										42
									
								
								.github/ISSUE_TEMPLATE.md
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										42
									
								
								.github/ISSUE_TEMPLATE.md
									
									
									
									
										vendored
									
									
								
							| @@ -1,31 +1,35 @@ | ||||
| <!-- | ||||
| DO NOT FILE ISSUES FOR GENERAL SUPPORT QUESTIONS. | ||||
|  | ||||
| The issue tracker is for reporting bugs and feature requests only. | ||||
| For end-user related support questions, refer to one of the following: | ||||
|  | ||||
| - Stack Overflow (using the "traefik" tag): https://stackoverflow.com/questions/tagged/traefik | ||||
| - the Traefik community Slack channel: https://traefik.herokuapp.com | ||||
|  | ||||
| --> | ||||
|  | ||||
| <!-- PLEASE FOLLOW THE ISSUE TEMPLATE TO HELP TRIAGE AND SUPPORT! --> | ||||
|  | ||||
| ### Do you want to request a *feature* or report a *bug*? | ||||
|  | ||||
| <!-- | ||||
| If you intend to ask a support question: DO NOT FILE AN ISSUE. | ||||
| DO NOT FILE ISSUES FOR GENERAL SUPPORT QUESTIONS. | ||||
|  | ||||
| The issue tracker is for reporting bugs and feature requests only. | ||||
| For end-user related support questions, please refer to one of the following: | ||||
|  | ||||
| - the Traefik community forum: https://community.traefik.io/ | ||||
|  | ||||
| --> | ||||
|  | ||||
| Bug | ||||
|  | ||||
| <!-- | ||||
|  | ||||
| The configurations between 1.X and 2.X are NOT compatible. | ||||
| Please have a look here https://doc.traefik.io/traefik/getting-started/configuration-overview/. | ||||
|  | ||||
| --> | ||||
|  | ||||
| ### What did you do? | ||||
|  | ||||
| <!-- | ||||
|  | ||||
| HOW TO WRITE A GOOD ISSUE? | ||||
| HOW TO WRITE A GOOD BUG REPORT? | ||||
|  | ||||
| - Respect the issue template as much as possible. | ||||
| - If it's possible use the command `traefik bug`. See https://www.youtube.com/watch?v=Lyz62L8m93I. | ||||
| - The title must be short and descriptive. | ||||
| - Explain the conditions which led you to write this issue: the context. | ||||
| - The title should be short and descriptive. | ||||
| - Explain the conditions which led you to report this issue: the context. | ||||
| - The context should lead to something, an idea or a problem that you’re facing. | ||||
| - Remain clear and concise. | ||||
| - Format your messages to help the reader focus on what matters and understand the structure of your message, use Markdown syntax https://help.github.com/articles/github-flavored-markdown | ||||
| @@ -43,9 +47,12 @@ HOW TO WRITE A GOOD ISSUE? | ||||
| ### Output of `traefik version`: (_What version of Traefik are you using?_) | ||||
|  | ||||
| <!-- | ||||
| `latest` is not considered as a valid version. | ||||
|  | ||||
| For the Traefik Docker image: | ||||
|     docker run [IMAGE] version | ||||
|     ex: docker run traefik version | ||||
|  | ||||
| --> | ||||
|  | ||||
| ``` | ||||
| @@ -57,12 +64,13 @@ For the Traefik Docker image: | ||||
| ```toml | ||||
| # (paste your configuration here) | ||||
| ``` | ||||
|  | ||||
| <!-- | ||||
| Add more configuration information here. | ||||
| --> | ||||
|  | ||||
|  | ||||
| ### If applicable, please paste the log output at DEBUG level (`--logLevel=DEBUG` switch) | ||||
| ### If applicable, please paste the log output in DEBUG level (`--log.level=DEBUG` switch) | ||||
|  | ||||
| ``` | ||||
| (paste your output here) | ||||
|   | ||||
							
								
								
									
										82
									
								
								.github/ISSUE_TEMPLATE/bug_report.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										82
									
								
								.github/ISSUE_TEMPLATE/bug_report.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,82 @@ | ||||
| name: Bug Report (Traefik) | ||||
| description: Create a report to help us improve. | ||||
| body: | ||||
|   - type: checkboxes | ||||
|     id: terms | ||||
|     attributes: | ||||
|       label: Welcome! | ||||
|       description: | | ||||
|         The issue tracker is for reporting bugs and feature requests only. | ||||
|         For end-user related support questions, please use the [Traefik community forum](https://community.traefik.io/). | ||||
|  | ||||
|         All new/updated issues are triaged regularly by the maintainers. | ||||
|         All issues closed by a bot are subsequently double-checked by the maintainers. | ||||
|  | ||||
|         DO NOT FILE ISSUES FOR GENERAL SUPPORT QUESTIONS. | ||||
|  | ||||
|       options: | ||||
|         - label: Yes, I've searched similar issues on [GitHub](https://github.com/traefik/traefik/issues) and didn't find any. | ||||
|           required: true | ||||
|         - label: Yes, I've searched similar issues on the [Traefik community forum](https://community.traefik.io) and didn't find any. | ||||
|           required: true | ||||
|  | ||||
|   - type: textarea | ||||
|     attributes: | ||||
|       label: What did you do? | ||||
|       description: | | ||||
|         How to write a good bug report? | ||||
|  | ||||
|         - Respect the issue template as much as possible. | ||||
|         - The title should be short and descriptive. | ||||
|         - Explain the conditions which led you to report this issue: the context. | ||||
|         - The context should lead to something, an idea or a problem that you’re facing. | ||||
|         - Remain clear and concise. | ||||
|         - Format your messages to help the reader focus on what matters and understand the structure of your message, use [Markdown syntax](https://help.github.com/articles/github-flavored-markdown) | ||||
|       placeholder: What did you do? | ||||
|     validations: | ||||
|       required: true | ||||
|  | ||||
|   - type: textarea | ||||
|     attributes: | ||||
|       label: What did you see instead? | ||||
|       placeholder: What did you see instead? | ||||
|     validations: | ||||
|       required: true | ||||
|  | ||||
|   - type: textarea | ||||
|     attributes: | ||||
|       label: What version of Traefik are you using? | ||||
|       description: | | ||||
|         `latest` is not considered as a valid version. | ||||
|  | ||||
|         Output of `traefik version`. | ||||
|  | ||||
|         For the Traefik Docker image (`docker run [IMAGE] version`), example: | ||||
|         ```console | ||||
|         $ docker run traefik version | ||||
|         ``` | ||||
|       placeholder: Paste your output here. | ||||
|     validations: | ||||
|       required: true | ||||
|  | ||||
|   - type: textarea | ||||
|     attributes: | ||||
|       label: What is your environment & configuration? | ||||
|       description: arguments, toml, provider, platform, ... | ||||
|       placeholder: Add information here. | ||||
|       value: | | ||||
|         ```yaml | ||||
|         # (paste your configuration here) | ||||
|         ``` | ||||
|  | ||||
|         Add more configuration information here. | ||||
|     validations: | ||||
|       required: true | ||||
|  | ||||
|   - type: textarea | ||||
|     attributes: | ||||
|       label: If applicable, please paste the log output in DEBUG level | ||||
|       description: "`--log.level=DEBUG` switch." | ||||
|       placeholder: Paste your output here. | ||||
|     validations: | ||||
|       required: false | ||||
							
								
								
									
										68
									
								
								.github/ISSUE_TEMPLATE/bugs.md
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										68
									
								
								.github/ISSUE_TEMPLATE/bugs.md
									
									
									
									
										vendored
									
									
								
							| @@ -1,68 +0,0 @@ | ||||
| <!-- | ||||
| DO NOT FILE ISSUES FOR GENERAL SUPPORT QUESTIONS. | ||||
|  | ||||
| The issue tracker is for reporting bugs and feature requests only. | ||||
| For end-user related support questions, refer to one of the following: | ||||
|  | ||||
| - Stack Overflow (using the "traefik" tag): https://stackoverflow.com/questions/tagged/traefik | ||||
| - the Traefik community Slack channel: https://traefik.herokuapp.com | ||||
|  | ||||
| --> | ||||
|  | ||||
|  | ||||
| ### Do you want to request a *feature* or report a *bug*? | ||||
|  | ||||
| Bug | ||||
|  | ||||
| ### What did you do? | ||||
|  | ||||
| <!-- | ||||
|  | ||||
| HOW TO WRITE A GOOD ISSUE? | ||||
|  | ||||
| - Respect the issue template as much as possible. | ||||
| - If it's possible use the command `traefik bug`. See https://www.youtube.com/watch?v=Lyz62L8m93I. | ||||
| - The title must be short and descriptive. | ||||
| - Explain the conditions which led you to write this issue: the context. | ||||
| - The context should lead to something, an idea or a problem that you’re facing. | ||||
| - Remain clear and concise. | ||||
| - Format your messages to help the reader focus on what matters and understand the structure of your message, use Markdown syntax https://help.github.com/articles/github-flavored-markdown | ||||
|  | ||||
| --> | ||||
|  | ||||
| ### What did you expect to see? | ||||
|  | ||||
|  | ||||
|  | ||||
| ### What did you see instead? | ||||
|  | ||||
|  | ||||
|  | ||||
| ### Output of `traefik version`: (_What version of Traefik are you using?_) | ||||
|  | ||||
| <!-- | ||||
| For the Traefik Docker image: | ||||
|     docker run [IMAGE] version | ||||
|     ex: docker run traefik version | ||||
| --> | ||||
|  | ||||
| ``` | ||||
| (paste your output here) | ||||
| ``` | ||||
|  | ||||
| ### What is your environment & configuration (arguments, toml, provider, platform, ...)? | ||||
|  | ||||
| ```toml | ||||
| # (paste your configuration here) | ||||
| ``` | ||||
|  | ||||
| <!-- | ||||
| Add more configuration information here. | ||||
| --> | ||||
|  | ||||
|  | ||||
| ### If applicable, please paste the log output in DEBUG level (`--logLevel=DEBUG` switch) | ||||
|  | ||||
| ``` | ||||
| (paste your output here) | ||||
| ``` | ||||
							
								
								
									
										8
									
								
								.github/ISSUE_TEMPLATE/config.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										8
									
								
								.github/ISSUE_TEMPLATE/config.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,8 @@ | ||||
| blank_issues_enabled: false | ||||
| contact_links: | ||||
|   - name: Traefik Community Support | ||||
|     url: https://community.traefik.io/ | ||||
|     about: If you have a question, or are looking for advice, please post on our Discuss forum! The community loves to chime in to help. Happy Coding! | ||||
|   - name: Traefik Helm Chart Issues | ||||
|     url: https://github.com/traefik/traefik-helm-chart | ||||
|     about: Are you submitting an issue or feature enhancement for the Traefik helm chart? Please post in the traefik-helm-chart GitHub Issues. | ||||
							
								
								
									
										33
									
								
								.github/ISSUE_TEMPLATE/feature-request.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										33
									
								
								.github/ISSUE_TEMPLATE/feature-request.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,33 @@ | ||||
| name: Feature Request (Traefik) | ||||
| description: Suggest an idea for this project. | ||||
| body: | ||||
|   - type: checkboxes | ||||
|     id: terms | ||||
|     attributes: | ||||
|       label: Welcome! | ||||
|       description: | | ||||
|         The issue tracker is for reporting bugs and feature requests only. For end-user related support questions, please refer to one of the following: | ||||
|         - the Traefik community forum: https://community.traefik.io/ | ||||
|  | ||||
|         DO NOT FILE ISSUES FOR GENERAL SUPPORT QUESTIONS. | ||||
|       options: | ||||
|         - label: Yes, I've searched similar issues on [GitHub](https://github.com/traefik/traefik/issues) and didn't find any. | ||||
|           required: true | ||||
|         - label: Yes, I've searched similar issues on the [Traefik community forum](https://community.traefik.io) and didn't find any. | ||||
|           required: true | ||||
|  | ||||
|   - type: textarea | ||||
|     attributes: | ||||
|       label: What did you expect to see? | ||||
|       description: | | ||||
|         How to write a good issue? | ||||
|  | ||||
|         - Respect the issue template as much as possible. | ||||
|         - The title should be short and descriptive. | ||||
|         - Explain the conditions which led you to report this issue: the context. | ||||
|         - The context should lead to something, an idea or a problem that you’re facing. | ||||
|         - Remain clear and concise. | ||||
|         - Format your messages to help the reader focus on what matters and understand the structure of your message, use [Markdown syntax](https://help.github.com/articles/github-flavored-markdown) | ||||
|       placeholder: What did you expect to see? | ||||
|     validations: | ||||
|       required: true | ||||
							
								
								
									
										32
									
								
								.github/ISSUE_TEMPLATE/features.md
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										32
									
								
								.github/ISSUE_TEMPLATE/features.md
									
									
									
									
										vendored
									
									
								
							| @@ -1,32 +0,0 @@ | ||||
| <!-- | ||||
| DO NOT FILE ISSUES FOR GENERAL SUPPORT QUESTIONS. | ||||
|  | ||||
| The issue tracker is for reporting bugs and feature requests only. | ||||
| For end-user related support questions, refer to one of the following: | ||||
|  | ||||
| - Stack Overflow (using the "traefik" tag): https://stackoverflow.com/questions/tagged/traefik | ||||
| - the Traefik community Slack channel: https://traefik.herokuapp.com | ||||
|  | ||||
| --> | ||||
|  | ||||
|  | ||||
| ### Do you want to request a *feature* or report a *bug*? | ||||
|  | ||||
| Feature | ||||
|  | ||||
| ### What did you expect to see? | ||||
|  | ||||
| <!-- | ||||
|  | ||||
| HOW TO WRITE A GOOD ISSUE? | ||||
|  | ||||
| - Respect the issue template as much as possible. | ||||
| - If it's possible use the command `traefik bug`. See https://www.youtube.com/watch?v=Lyz62L8m93I. | ||||
| - The title must be short and descriptive. | ||||
| - Explain the conditions which led you to write this issue: the context. | ||||
| - The context should lead to something, an idea or a problem that you’re facing. | ||||
| - Remain clear and concise. | ||||
| - Format your messages to help the reader focus on what matters and understand the structure of your message, use Markdown syntax https://help.github.com/articles/github-flavored-markdown | ||||
|  | ||||
| --> | ||||
|  | ||||
							
								
								
									
										23
									
								
								.github/PULL_REQUEST_TEMPLATE.md
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										23
									
								
								.github/PULL_REQUEST_TEMPLATE.md
									
									
									
									
										vendored
									
									
								
							| @@ -1,18 +1,19 @@ | ||||
| <!-- | ||||
| PLEASE READ THIS MESSAGE. | ||||
|  | ||||
| HOW TO WRITE A GOOD PULL REQUEST? | ||||
| Documentation fixes or enhancements: | ||||
| - for Traefik v2: use branch v2.11 | ||||
| - for Traefik v3: use branch v3.1 | ||||
|  | ||||
| - Make it small. | ||||
| - Do only one thing. | ||||
| - Avoid re-formatting. | ||||
| - Make sure the code builds. | ||||
| - Make sure all tests pass. | ||||
| - Add tests. | ||||
| - Write useful descriptions and titles. | ||||
| - Address review comments in terms of additional commits. | ||||
| - Do not amend/squash existing ones unless the PR is trivial. | ||||
| - Read the contributing guide: https://github.com/containous/traefik/blob/master/.github/CONTRIBUTING.md. | ||||
| Bug fixes: | ||||
| - for Traefik v2: use branch v2.11 | ||||
| - for Traefik v3: use branch v3.1 | ||||
|  | ||||
| Enhancements: | ||||
| - for Traefik v2: we only accept bug fixes | ||||
| - for Traefik v3: use branch master | ||||
|  | ||||
| HOW TO WRITE A GOOD PULL REQUEST? https://doc.traefik.io/traefik/contributing/submitting-pull-requests/ | ||||
|  | ||||
| --> | ||||
|  | ||||
|   | ||||
							
								
								
									
										78
									
								
								.github/workflows/build.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										78
									
								
								.github/workflows/build.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,78 @@ | ||||
| name: Build Binaries | ||||
|  | ||||
| on: | ||||
|   pull_request: | ||||
|     branches: | ||||
|       - '*' | ||||
|     paths-ignore: | ||||
|       - 'docs/**' | ||||
|       - '**.md' | ||||
|       - 'script/gcg/**' | ||||
|  | ||||
| env: | ||||
|   GO_VERSION: '1.22' | ||||
|   CGO_ENABLED: 0 | ||||
|  | ||||
| jobs: | ||||
|  | ||||
|   build-webui: | ||||
|     runs-on: ubuntu-latest | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Setup node | ||||
|         uses: actions/setup-node@v4 | ||||
|         with: | ||||
|           node-version-file: webui/.nvmrc | ||||
|           cache: yarn | ||||
|           cache-dependency-path: webui/yarn.lock | ||||
|  | ||||
|       - name: Build webui | ||||
|         working-directory: ./webui | ||||
|         run: | | ||||
|           yarn install | ||||
|           yarn build | ||||
|  | ||||
|       - name: Package webui | ||||
|         run: | | ||||
|           tar czvf webui.tar.gz ./webui/static/ | ||||
|  | ||||
|       - name: Artifact webui | ||||
|         uses: actions/upload-artifact@v4 | ||||
|         with: | ||||
|           name: webui.tar.gz | ||||
|           path: webui.tar.gz | ||||
|  | ||||
|   build: | ||||
|     runs-on: ${{ matrix.os }} | ||||
|     strategy: | ||||
|       matrix: | ||||
|         os: [ ubuntu-latest, macos-latest, windows-latest ] | ||||
|     needs: | ||||
|       - build-webui | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Set up Go ${{ env.GO_VERSION }} | ||||
|         uses: actions/setup-go@v5 | ||||
|         with: | ||||
|           go-version: ${{ env.GO_VERSION }} | ||||
|  | ||||
|       - name: Artifact webui | ||||
|         uses: actions/download-artifact@v4 | ||||
|         with: | ||||
|           name: webui.tar.gz | ||||
|  | ||||
|       - name: Untar webui | ||||
|         run: tar xvf webui.tar.gz | ||||
|  | ||||
|       - name: Build | ||||
|         run: make binary | ||||
							
								
								
									
										25
									
								
								.github/workflows/check_doc.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										25
									
								
								.github/workflows/check_doc.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,25 @@ | ||||
| name: Check Documentation | ||||
|  | ||||
| on: | ||||
|   pull_request: | ||||
|     branches: | ||||
|       - '*' | ||||
|  | ||||
| jobs: | ||||
|  | ||||
|   docs: | ||||
|     name: Check, verify and build documentation | ||||
|     runs-on: ubuntu-latest | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Check documentation | ||||
|         run: make docs-pull-images docs | ||||
|         env: | ||||
|           # These variables are not passed to workflows that are triggered by a pull request from a fork. | ||||
|           DOCS_VERIFY_SKIP: ${{ vars.DOCS_VERIFY_SKIP }} | ||||
|           DOCS_LINT_SKIP: ${{ vars.DOCS_LINT_SKIP }} | ||||
							
								
								
									
										70
									
								
								.github/workflows/codeql.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										70
									
								
								.github/workflows/codeql.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,70 @@ | ||||
| name: "CodeQL" | ||||
|  | ||||
| on: | ||||
|   push: | ||||
|     branches: | ||||
|       - master | ||||
|       - v* | ||||
|   schedule: | ||||
|     - cron: '11 22 * * 1' | ||||
|  | ||||
| jobs: | ||||
|   analyze: | ||||
|     name: Analyze | ||||
|     runs-on: ubuntu-latest | ||||
|     permissions: | ||||
|       actions: read | ||||
|       contents: read | ||||
|       security-events: write | ||||
|  | ||||
|     strategy: | ||||
|       fail-fast: false | ||||
|       matrix: | ||||
|         language: [ 'javascript', 'go' ] | ||||
|         # CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python', 'ruby' ] | ||||
|         # Use only 'java' to analyze code written in Java, Kotlin or both | ||||
|         # Use only 'javascript' to analyze code written in JavaScript, TypeScript or both | ||||
|         # Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support | ||||
|  | ||||
|     steps: | ||||
|     - name: Checkout repository | ||||
|       uses: actions/checkout@v4 | ||||
|  | ||||
|     - name: setup go | ||||
|       uses: actions/setup-go@v5 | ||||
|       if: ${{ matrix.language == 'go' }} | ||||
|       with: | ||||
|         go-version-file: 'go.mod' | ||||
|  | ||||
|     # Initializes the CodeQL tools for scanning. | ||||
|     - name: Initialize CodeQL | ||||
|       uses: github/codeql-action/init@v3 | ||||
|       with: | ||||
|         languages: ${{ matrix.language }} | ||||
|         # If you wish to specify custom queries, you can do so here or in a config file. | ||||
|         # By default, queries listed here will override any specified in a config file. | ||||
|         # Prefix the list here with "+" to use these queries and those in the config file. | ||||
|  | ||||
|         # For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs | ||||
|         # queries: security-extended,security-and-quality | ||||
|  | ||||
|  | ||||
|     # Autobuild attempts to build any compiled languages (C/C++, C#, Go, Java, or Swift). | ||||
|     # If this step fails, then you should remove it and run the build manually (see below) | ||||
|     - name: Autobuild | ||||
|       uses: github/codeql-action/autobuild@v3 | ||||
|  | ||||
|     # ℹ️ Command-line programs to run using the OS shell. | ||||
|     # 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun | ||||
|  | ||||
|     #   If the Autobuild fails above, remove it and uncomment the following three lines. | ||||
|     #   modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance. | ||||
|  | ||||
|     # - run: | | ||||
|     #     echo "Run, Build Application using script" | ||||
|     #     ./location_of_script_within_repo/buildscript.sh | ||||
|  | ||||
|     - name: Perform CodeQL Analysis | ||||
|       uses: github/codeql-action/analyze@v3 | ||||
|       with: | ||||
|         category: "/language:${{matrix.language}}" | ||||
							
								
								
									
										52
									
								
								.github/workflows/documentation.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										52
									
								
								.github/workflows/documentation.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,52 @@ | ||||
| name: Build and Publish Documentation | ||||
|  | ||||
| on: | ||||
|   push: | ||||
|     branches: | ||||
|       - master | ||||
|       - v* | ||||
|  | ||||
| env: | ||||
|   STRUCTOR_VERSION: v1.13.2 | ||||
|   MIXTUS_VERSION: v0.4.1 | ||||
|  | ||||
| jobs: | ||||
|  | ||||
|   docs: | ||||
|     name: Doc Process | ||||
|     runs-on: ubuntu-latest | ||||
|     if: github.repository == 'traefik/traefik' | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Login to DockerHub | ||||
|         uses: docker/login-action@v3 | ||||
|         with: | ||||
|           username: ${{ secrets.DOCKERHUB_USERNAME }} | ||||
|           password: ${{ secrets.DOCKERHUB_TOKEN }} | ||||
|  | ||||
|       - name: Install Structor ${{ env.STRUCTOR_VERSION }} | ||||
|         run: curl -sSfL https://raw.githubusercontent.com/traefik/structor/master/godownloader.sh | sh -s -- -b $HOME/bin ${STRUCTOR_VERSION} | ||||
|  | ||||
|       - name: Install Seo-doc | ||||
|         run: curl -sSfL https://raw.githubusercontent.com/traefik/seo-doc/master/godownloader.sh | sh -s -- -b "${HOME}/bin" | ||||
|  | ||||
|       - name: Install Mixtus ${{ env.MIXTUS_VERSION }} | ||||
|         run: curl -sSfL https://raw.githubusercontent.com/traefik/mixtus/master/godownloader.sh | sh -s -- -b $HOME/bin ${MIXTUS_VERSION} | ||||
|  | ||||
|       - name: Build documentation | ||||
|         run: $HOME/bin/structor -o traefik -r traefik --dockerfile-url="https://raw.githubusercontent.com/traefik/traefik/v1.7/docs.Dockerfile" --menu.js-url="https://raw.githubusercontent.com/traefik/structor/master/traefik-menu.js.gotmpl" --rqts-url="https://raw.githubusercontent.com/traefik/structor/master/requirements-override.txt" --force-edit-url --exp-branch=master --debug | ||||
|         env: | ||||
|           STRUCTOR_LATEST_TAG: ${{ vars.STRUCTOR_LATEST_TAG }} | ||||
|  | ||||
|       - name: Apply seo | ||||
|         run: $HOME/bin/seo -path=./site -product=traefik | ||||
|  | ||||
|       - name: Publish documentation | ||||
|         run: $HOME/bin/mixtus --dst-doc-path="./traefik" --dst-owner=traefik --dst-repo-name=doc --git-user-email="30906710+traefiker@users.noreply.github.com" --git-user-name=traefiker --src-doc-path="./site" --src-owner=traefik --src-repo-name=traefik | ||||
|         env: | ||||
|           GITHUB_TOKEN: ${{ secrets.GH_TOKEN_REPO }} | ||||
							
								
								
									
										68
									
								
								.github/workflows/experimental.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										68
									
								
								.github/workflows/experimental.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,68 @@ | ||||
| name: Build experimental image on branch | ||||
|  | ||||
| on: | ||||
|   push: | ||||
|     branches: | ||||
|       - master | ||||
|       - v* | ||||
|  | ||||
| env: | ||||
|   GO_VERSION: '1.22' | ||||
|   CGO_ENABLED: 0 | ||||
|  | ||||
| jobs: | ||||
|  | ||||
|   experimental: | ||||
|     if: github.repository == 'traefik/traefik' | ||||
|     name: Build experimental image on branch | ||||
|     runs-on: ubuntu-latest | ||||
|  | ||||
|     steps: | ||||
|  | ||||
|       # https://github.com/marketplace/actions/checkout | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Setup node | ||||
|         uses: actions/setup-node@v4 | ||||
|         with: | ||||
|           node-version-file: webui/.nvmrc | ||||
|           cache: yarn | ||||
|           cache-dependency-path: webui/yarn.lock | ||||
|  | ||||
|       - name: Build webui | ||||
|         working-directory: ./webui | ||||
|         run: | | ||||
|           yarn install | ||||
|           yarn build | ||||
|  | ||||
|       - name: Set up Go ${{ env.GO_VERSION }} | ||||
|         uses: actions/setup-go@v5 | ||||
|         with: | ||||
|           go-version: ${{ env.GO_VERSION }} | ||||
|  | ||||
|       - name: Build | ||||
|         run: make generate binary | ||||
|  | ||||
|       - name: Branch name | ||||
|         run: echo ${GITHUB_REF##*/} | ||||
|  | ||||
|       - name: Login to Docker Hub | ||||
|         uses: docker/login-action@v3 | ||||
|         with: | ||||
|           username: ${{ secrets.DOCKERHUB_USERNAME }} | ||||
|           password: ${{ secrets.DOCKERHUB_TOKEN }} | ||||
|  | ||||
|       - name: Set up QEMU | ||||
|         uses: docker/setup-qemu-action@v3 | ||||
|  | ||||
|       - name: Set up Docker Buildx | ||||
|         uses: docker/setup-buildx-action@v3 | ||||
|  | ||||
|       - name: Build docker experimental image | ||||
|         env: | ||||
|           DOCKER_BUILDX_ARGS: "--push" | ||||
|         run: | | ||||
|           make multi-arch-image-experimental-${GITHUB_REF##*/} | ||||
							
								
								
									
										35
									
								
								.github/workflows/test-conformance.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										35
									
								
								.github/workflows/test-conformance.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,35 @@ | ||||
| name: Test K8s Gateway API conformance | ||||
|  | ||||
| on: | ||||
|   pull_request: | ||||
|     branches: | ||||
|       - '*' | ||||
|     paths: | ||||
|       - 'pkg/provider/kubernetes/gateway/**' | ||||
|       - 'integration/k8s_conformance_test.go' | ||||
|  | ||||
| env: | ||||
|   GO_VERSION: '1.22' | ||||
|   CGO_ENABLED: 0 | ||||
|  | ||||
| jobs: | ||||
|  | ||||
|   test-conformance: | ||||
|     runs-on: ubuntu-latest | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Set up Go ${{ env.GO_VERSION }} | ||||
|         uses: actions/setup-go@v5 | ||||
|         with: | ||||
|           go-version: ${{ env.GO_VERSION }} | ||||
|  | ||||
|       - name: Avoid generating webui | ||||
|         run: touch webui/static/index.html | ||||
|  | ||||
|       - name: K8s Gateway API conformance test | ||||
|         run: make test-gateway-api-conformance | ||||
							
								
								
									
										76
									
								
								.github/workflows/test-integration.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										76
									
								
								.github/workflows/test-integration.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,76 @@ | ||||
| name: Test Integration | ||||
|  | ||||
| on: | ||||
|   pull_request: | ||||
|     branches: | ||||
|       - '*' | ||||
|     paths-ignore: | ||||
|       - 'docs/**' | ||||
|       - '**.md' | ||||
|       - 'script/gcg/**' | ||||
|  | ||||
| env: | ||||
|   GO_VERSION: '1.22' | ||||
|   CGO_ENABLED: 0 | ||||
|  | ||||
| jobs: | ||||
|  | ||||
|   build: | ||||
|     runs-on: ubuntu-latest | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Set up Go ${{ env.GO_VERSION }} | ||||
|         uses: actions/setup-go@v5 | ||||
|         with: | ||||
|           go-version: ${{ env.GO_VERSION }} | ||||
|  | ||||
|       - name: Avoid generating webui | ||||
|         run: touch webui/static/index.html | ||||
|  | ||||
|       - name: Build binary | ||||
|         run: make binary | ||||
|  | ||||
|   test-integration: | ||||
|     runs-on: ubuntu-latest | ||||
|     needs: | ||||
|       - build | ||||
|     strategy: | ||||
|       fail-fast: true | ||||
|       matrix: | ||||
|         parallel: [12] | ||||
|         index: [0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11] | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Set up Go ${{ env.GO_VERSION }} | ||||
|         uses: actions/setup-go@v5 | ||||
|         with: | ||||
|           go-version: ${{ env.GO_VERSION }} | ||||
|  | ||||
|       - name: Avoid generating webui | ||||
|         run: touch webui/static/index.html | ||||
|  | ||||
|       - name: Build binary | ||||
|         run: make binary | ||||
|  | ||||
|       - name: Generate go test Slice | ||||
|         id: test_split | ||||
|         uses: hashicorp-forge/go-test-split-action@v2.0.0 | ||||
|         with: | ||||
|           packages: ./integration | ||||
|           total: ${{ matrix.parallel }} | ||||
|           index: ${{ matrix.index }} | ||||
|  | ||||
|       - name: Run Integration tests | ||||
|         run: | | ||||
|           TESTS=$(echo "${{ steps.test_split.outputs.run}}" | sed 's/\$/\$\$/g') | ||||
|           TESTFLAGS="-run \"${TESTS}\"" make test-integration | ||||
							
								
								
									
										56
									
								
								.github/workflows/test-unit.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										56
									
								
								.github/workflows/test-unit.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,56 @@ | ||||
| name: Test Unit | ||||
|  | ||||
| on: | ||||
|   pull_request: | ||||
|     branches: | ||||
|       - '*' | ||||
|     paths-ignore: | ||||
|       - 'docs/**' | ||||
|       - '**.md' | ||||
|       - 'script/gcg/**' | ||||
|  | ||||
| env: | ||||
|   GO_VERSION: '1.22' | ||||
|  | ||||
| jobs: | ||||
|  | ||||
|   test-unit: | ||||
|     runs-on: ubuntu-latest | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Set up Go ${{ env.GO_VERSION }} | ||||
|         uses: actions/setup-go@v5 | ||||
|         with: | ||||
|           go-version: ${{ env.GO_VERSION }} | ||||
|  | ||||
|       - name: Avoid generating webui | ||||
|         run: touch webui/static/index.html | ||||
|  | ||||
|       - name: Tests | ||||
|         run: make test-unit | ||||
|  | ||||
|   test-ui-unit: | ||||
|     runs-on: ubuntu-latest | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Set up Node.js ${{ env.NODE_VERSION }} | ||||
|         uses: actions/setup-node@v4 | ||||
|         with: | ||||
|           node-version-file: webui/.nvmrc | ||||
|           cache: 'yarn' | ||||
|           cache-dependency-path: webui/yarn.lock | ||||
|  | ||||
|       - name: UI unit tests | ||||
|         run: | | ||||
|           yarn --cwd webui install | ||||
|           yarn --cwd webui test:unit:ci | ||||
							
								
								
									
										68
									
								
								.github/workflows/validate.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										68
									
								
								.github/workflows/validate.yaml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,68 @@ | ||||
| name: Validate | ||||
|  | ||||
| on: | ||||
|   pull_request: | ||||
|     branches: | ||||
|       - '*' | ||||
|  | ||||
| env: | ||||
|   GO_VERSION: '1.22' | ||||
|   GOLANGCI_LINT_VERSION: v1.59.0 | ||||
|   MISSSPELL_VERSION: v0.6.0 | ||||
|  | ||||
| jobs: | ||||
|  | ||||
|   validate: | ||||
|     runs-on: ubuntu-latest | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Set up Go ${{ env.GO_VERSION }} | ||||
|         uses: actions/setup-go@v5 | ||||
|         with: | ||||
|           go-version: ${{ env.GO_VERSION }} | ||||
|  | ||||
|       - name: Install golangci-lint ${{ env.GOLANGCI_LINT_VERSION }} | ||||
|         run: curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(go env GOPATH)/bin ${GOLANGCI_LINT_VERSION} | ||||
|  | ||||
|       - name: Install missspell ${{ env.MISSSPELL_VERSION }} | ||||
|         run: curl -sfL https://raw.githubusercontent.com/golangci/misspell/master/install-misspell.sh | sh -s -- -b $(go env GOPATH)/bin ${MISSSPELL_VERSION} | ||||
|  | ||||
|       - name: Avoid generating webui | ||||
|         run: touch webui/static/index.html | ||||
|  | ||||
|       - name: Validate | ||||
|         run: make validate | ||||
|  | ||||
|   validate-generate: | ||||
|     runs-on: ubuntu-latest | ||||
|  | ||||
|     steps: | ||||
|       - name: Check out code | ||||
|         uses: actions/checkout@v4 | ||||
|         with: | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: Set up Go ${{ env.GO_VERSION }} | ||||
|         uses: actions/setup-go@v5 | ||||
|         with: | ||||
|           go-version: ${{ env.GO_VERSION }} | ||||
|  | ||||
|       - name: go generate | ||||
|         run: | | ||||
|           make generate | ||||
|           git diff --exit-code | ||||
|  | ||||
|       - name: go mod tidy | ||||
|         run: | | ||||
|           go mod tidy | ||||
|           git diff --exit-code | ||||
|  | ||||
|       - name: make generate-crd | ||||
|         run: | | ||||
|           make generate-crd | ||||
|           git diff --exit-code | ||||
							
								
								
									
										22
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										22
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							| @@ -1,14 +1,22 @@ | ||||
| /dist | ||||
| /autogen/genstatic/gen.go | ||||
| .idea/ | ||||
| .intellij/ | ||||
| *.iml | ||||
| .vscode/ | ||||
| .DS_Store | ||||
| /dist | ||||
| /webui/.tmp/ | ||||
| /site/ | ||||
| /docs/site/ | ||||
| /autogen/ | ||||
| /traefik | ||||
| /traefik.toml | ||||
| /static/ | ||||
| .vscode/ | ||||
| /site/ | ||||
| /traefik.yml | ||||
| *.log | ||||
| *.exe | ||||
| .DS_Store | ||||
| /examples/acme/acme.json | ||||
| cover.out | ||||
| vendor/ | ||||
| plugins-storage/ | ||||
| plugins-local/ | ||||
| traefik_changelog.md | ||||
| integration/tailscale.secret | ||||
| integration/conformance-reports/ | ||||
|   | ||||
							
								
								
									
										282
									
								
								.golangci.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										282
									
								
								.golangci.yml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,282 @@ | ||||
| run: | ||||
|   timeout: 10m | ||||
|  | ||||
| linters-settings: | ||||
|   govet: | ||||
|     enable-all: true | ||||
|     disable: | ||||
|       - shadow | ||||
|       - fieldalignment | ||||
|   gocyclo: | ||||
|     min-complexity: 14 | ||||
|   goconst: | ||||
|     min-len: 3 | ||||
|     min-occurrences: 4 | ||||
|   misspell: | ||||
|     locale: US | ||||
|   funlen: | ||||
|     lines: -1 | ||||
|     statements: 120 | ||||
|   forbidigo: | ||||
|     forbid: | ||||
|       - ^print(ln)?$ | ||||
|       - ^spew\.Print(f|ln)?$ | ||||
|       - ^spew\.Dump$ | ||||
|   depguard: | ||||
|     rules: | ||||
|       main: | ||||
|         deny: | ||||
|           - pkg: "github.com/instana/testify" | ||||
|             desc: not allowed | ||||
|           - pkg: "github.com/pkg/errors" | ||||
|             desc: Should be replaced by standard lib errors package | ||||
|           - pkg: "k8s.io/api/networking/v1beta1" | ||||
|             desc: This API is deprecated | ||||
|           - pkg: "k8s.io/api/extensions/v1beta1" | ||||
|             desc: This API is deprecated | ||||
|   godox: | ||||
|     keywords: | ||||
|       - FIXME | ||||
|   importas: | ||||
|     no-unaliased: true | ||||
|     alias: | ||||
|       - alias: composeapi | ||||
|         pkg: github.com/docker/compose/v2/pkg/api | ||||
|  | ||||
|       # Standard Kubernetes rewrites: | ||||
|       - alias: corev1 | ||||
|         pkg: "k8s.io/api/core/v1" | ||||
|       - alias: netv1 | ||||
|         pkg: "k8s.io/api/networking/v1" | ||||
|       - alias: admv1 | ||||
|         pkg: "k8s.io/api/admission/v1" | ||||
|       - alias: admv1beta1 | ||||
|         pkg: "k8s.io/api/admission/v1beta1" | ||||
|       - alias: metav1 | ||||
|         pkg: "k8s.io/apimachinery/pkg/apis/meta/v1" | ||||
|       - alias: ktypes | ||||
|         pkg: "k8s.io/apimachinery/pkg/types" | ||||
|       - alias: kerror | ||||
|         pkg: "k8s.io/apimachinery/pkg/api/errors" | ||||
|       - alias: kclientset | ||||
|         pkg: "k8s.io/client-go/kubernetes" | ||||
|       - alias: kinformers | ||||
|         pkg: "k8s.io/client-go/informers" | ||||
|       - alias: ktesting | ||||
|         pkg: "k8s.io/client-go/testing" | ||||
|       - alias: kschema | ||||
|         pkg: "k8s.io/apimachinery/pkg/runtime/schema" | ||||
|       - alias: kscheme | ||||
|         pkg: "k8s.io/client-go/kubernetes/scheme" | ||||
|       - alias: kversion | ||||
|         pkg: "k8s.io/apimachinery/pkg/version" | ||||
|       - alias: kubefake | ||||
|         pkg: "k8s.io/client-go/kubernetes/fake" | ||||
|       - alias: discoveryfake | ||||
|         pkg: "k8s.io/client-go/discovery/fake" | ||||
|  | ||||
|       # Kubernetes Gateway rewrites: | ||||
|       - alias: gateclientset | ||||
|         pkg: "sigs.k8s.io/gateway-api/pkg/client/clientset/gateway/versioned" | ||||
|       - alias: gateinformers | ||||
|         pkg: "sigs.k8s.io/gateway-api/pkg/client/informers/gateway/externalversions" | ||||
|       - alias: gatev1alpha2 | ||||
|         pkg: "sigs.k8s.io/gateway-api/apis/v1alpha2" | ||||
|  | ||||
|       # Traefik Kubernetes rewrites: | ||||
|       - alias: traefikv1alpha1 | ||||
|         pkg: "github.com/traefik/traefik/v3/pkg/provider/kubernetes/crd/traefikio/v1alpha1" | ||||
|       - alias: traefikclientset | ||||
|         pkg: "github.com/traefik/traefik/v3/pkg/provider/kubernetes/crd/generated/clientset/versioned" | ||||
|       - alias: traefikinformers | ||||
|         pkg: "github.com/traefik/traefik/v3/pkg/provider/kubernetes/crd/generated/informers/externalversions" | ||||
|       - alias: traefikscheme | ||||
|         pkg: "github.com/traefik/traefik/v3/pkg/provider/kubernetes/crd/generated/clientset/versioned/scheme" | ||||
|       - alias: traefikcrdfake | ||||
|         pkg: "github.com/traefik/traefik/v3/pkg/provider/kubernetes/crd/generated/clientset/versioned/fake" | ||||
|   tagalign: | ||||
|     align: false | ||||
|     sort: true | ||||
|     order: | ||||
|       - description | ||||
|       - json | ||||
|       - toml | ||||
|       - yaml | ||||
|       - yml | ||||
|       - label | ||||
|       - label-slice-as-struct | ||||
|       - file | ||||
|       - kv | ||||
|       - export | ||||
|   revive: | ||||
|     rules: | ||||
|       - name: struct-tag | ||||
|       - name: blank-imports | ||||
|       - name: context-as-argument | ||||
|       - name: context-keys-type | ||||
|       - name: dot-imports | ||||
|       - name: error-return | ||||
|       - name: error-strings | ||||
|       - name: error-naming | ||||
|       - name: exported | ||||
|         disabled: true | ||||
|       - name: if-return | ||||
|       - name: increment-decrement | ||||
|       - name: var-naming | ||||
|       - name: var-declaration | ||||
|       - name: package-comments | ||||
|         disabled: true | ||||
|       - name: range | ||||
|       - name: receiver-naming | ||||
|       - name: time-naming | ||||
|       - name: unexported-return | ||||
|       - name: indent-error-flow | ||||
|       - name: errorf | ||||
|       - name: empty-block | ||||
|       - name: superfluous-else | ||||
|       - name: unused-parameter | ||||
|         disabled: true | ||||
|       - name: unreachable-code | ||||
|       - name: redefines-builtin-id | ||||
|   gomoddirectives: | ||||
|     replace-allow-list: | ||||
|       - github.com/abbot/go-http-auth | ||||
|       - github.com/gorilla/mux | ||||
|       - github.com/mailgun/minheap | ||||
|       - github.com/mailgun/multibuf | ||||
|       - github.com/jaguilar/vt100 | ||||
|       - github.com/cucumber/godog | ||||
|       - github.com/http-wasm/http-wasm-host-go | ||||
|   testifylint: | ||||
|     disable: | ||||
|       - suite-dont-use-pkg | ||||
|       - require-error | ||||
|       - go-require | ||||
|   staticcheck: | ||||
|     checks: | ||||
|       - all | ||||
|       - -SA1019 | ||||
|   errcheck: | ||||
|     exclude-functions: | ||||
|       - fmt.Fprintln | ||||
| linters: | ||||
|   enable-all: true | ||||
|   disable: | ||||
|     - execinquery # deprecated | ||||
|     - gomnd # deprecated | ||||
|     - sqlclosecheck # not relevant (SQL) | ||||
|     - rowserrcheck # not relevant (SQL) | ||||
|     - cyclop # duplicate of gocyclo | ||||
|     - lll # Not relevant | ||||
|     - gocyclo # FIXME must be fixed | ||||
|     - gocognit # Too strict | ||||
|     - nestif # Too many false-positive. | ||||
|     - prealloc # Too many false-positive. | ||||
|     - makezero # Not relevant | ||||
|     - dupl # Too strict | ||||
|     - gosec # Too strict | ||||
|     - gochecknoinits | ||||
|     - gochecknoglobals | ||||
|     - wsl # Too strict | ||||
|     - nlreturn # Not relevant | ||||
|     - mnd # Too strict | ||||
|     - stylecheck # skip because report issues related to some generated files. | ||||
|     - testpackage # Too strict | ||||
|     - tparallel # Not relevant | ||||
|     - paralleltest # Not relevant | ||||
|     - exhaustive # Not relevant | ||||
|     - exhaustruct # Not relevant | ||||
|     - err113 # Too strict | ||||
|     - wrapcheck # Too strict | ||||
|     - noctx # Too strict | ||||
|     - bodyclose # too many false-positive | ||||
|     - forcetypeassert # Too strict | ||||
|     - tagliatelle # Too strict | ||||
|     - varnamelen # Not relevant | ||||
|     - nilnil # Not relevant | ||||
|     - ireturn # Not relevant | ||||
|     - contextcheck # too many false-positive | ||||
|     - containedctx # too many false-positive | ||||
|     - maintidx # kind of duplicate of gocyclo | ||||
|     - nonamedreturns # Too strict | ||||
|     - gosmopolitan  # not relevant | ||||
|     - exportloopref # Useless with go1.22 | ||||
|     - musttag | ||||
|  | ||||
| issues: | ||||
|   exclude-use-default: false | ||||
|   max-issues-per-linter: 0 | ||||
|   max-same-issues: 0 | ||||
|   exclude-dirs: | ||||
|     - pkg/provider/kubernetes/crd/generated/ | ||||
|   exclude: | ||||
|     - 'Error return value of .((os\.)?std(out|err)\..*|.*Close|.*Flush|os\.Remove(All)?|.*printf?|os\.(Un)?Setenv). is not checked' | ||||
|     - "should have a package comment, unless it's in another file for this package" | ||||
|     - 'fmt.Sprintf can be replaced with string' | ||||
|   exclude-rules: | ||||
|     - path: '(.+)_test.go' | ||||
|       linters: | ||||
|         - goconst | ||||
|         - funlen | ||||
|         - godot | ||||
|         - canonicalheader | ||||
|         - fatcontext | ||||
|     - path: '(.+)_test.go' | ||||
|       text: ' always receives ' | ||||
|       linters: | ||||
|         - unparam | ||||
|     - path: '(.+)\.go' | ||||
|       text: 'struct-tag: unknown option ''inline'' in JSON tag' | ||||
|       linters: | ||||
|         - revive | ||||
|     - path: pkg/server/service/bufferpool.go | ||||
|       text: 'SA6002: argument should be pointer-like to avoid allocations' | ||||
|     - path: pkg/server/middleware/middlewares.go | ||||
|       text: "Function 'buildConstructor' has too many statements" | ||||
|       linters: | ||||
|         - funlen | ||||
|     - path: pkg/logs/haystack.go | ||||
|       linters: | ||||
|         - goprintffuncname | ||||
|     - path: pkg/tracing/tracing.go | ||||
|       text: "printf-like formatting function 'SetErrorWithEvent' should be named 'SetErrorWithEventf'" | ||||
|       linters: | ||||
|         - goprintffuncname | ||||
|     - path: pkg/tls/tlsmanager_test.go | ||||
|       text: 'SA1019: config.ClientCAs.Subjects has been deprecated since Go 1.18' | ||||
|     - path: pkg/types/tls_test.go | ||||
|       text: 'SA1019: tlsConfig.RootCAs.Subjects has been deprecated since Go 1.18' | ||||
|     - path: pkg/provider/kubernetes/crd/kubernetes.go | ||||
|       text: 'SA1019: middleware.Spec.IPWhiteList is deprecated: please use IPAllowList instead.' | ||||
|     - path: pkg/server/middleware/tcp/middlewares.go | ||||
|       text: 'SA1019: config.IPWhiteList is deprecated: please use IPAllowList instead.' | ||||
|     - path: pkg/server/middleware/middlewares.go | ||||
|       text: 'SA1019: config.IPWhiteList is deprecated: please use IPAllowList instead.' | ||||
|     - path: pkg/provider/kubernetes/(crd|gateway)/client.go | ||||
|       linters: | ||||
|         - interfacebloat | ||||
|     - path: pkg/metrics/metrics.go | ||||
|       linters: | ||||
|         - interfacebloat | ||||
|     - path: integration/healthcheck_test.go | ||||
|       text: 'Duplicate words \(wsp2,\) found' | ||||
|       linters: | ||||
|         - dupword | ||||
|     - path: pkg/types/domain_test.go | ||||
|       text: 'Duplicate words \(sub\) found' | ||||
|       linters: | ||||
|         - dupword | ||||
|     - path: pkg/provider/kubernetes/crd/kubernetes.go | ||||
|       text: "Function 'loadConfigurationFromCRD' has too many statements" | ||||
|       linters: | ||||
|         - funlen | ||||
|     - path: pkg/provider/kubernetes/gateway/client_mock_test.go | ||||
|       text: 'unusedwrite: unused write to field' | ||||
|       linters: | ||||
|         - govet | ||||
|     - path: pkg/cli/deprecation.go | ||||
|       linters: | ||||
|         - goconst | ||||
|     - path: pkg/cli/loader_file.go | ||||
|       linters: | ||||
|         - goconst | ||||
| @@ -1,42 +0,0 @@ | ||||
| { | ||||
|   "Vendor": true, | ||||
|   "Sort": [ | ||||
|     "path", | ||||
|     "line", | ||||
|     "column", | ||||
|     "severity", | ||||
|     "linter" | ||||
|   ], | ||||
|   "Test": true, | ||||
|   "Cyclo": 15, | ||||
|   "Enable": [ | ||||
|     "gotypex", | ||||
|     "nakedret", | ||||
|     "vet", | ||||
|     "goimports", | ||||
|     "golint", | ||||
|     "ineffassign", | ||||
|     "gotype", | ||||
|     "misspell", | ||||
|     "structcheck", | ||||
|     "gosimple", | ||||
|     "unconvert", | ||||
|     "varcheck", | ||||
|     "errcheck", | ||||
|     "unused", | ||||
|     "deadcode", | ||||
|     "staticcheck" | ||||
|   ], | ||||
|   "Disable": [ | ||||
|     "gas", | ||||
|     "maligned", | ||||
|     "interfacer", | ||||
|     "goconst", | ||||
|     "gocyclo", | ||||
|     "vetshadow" | ||||
|   ], | ||||
|   "Exclude": [ | ||||
|     "autogen/.*" | ||||
|   ], | ||||
|   "Deadline": "5m" | ||||
| } | ||||
							
								
								
									
										66
									
								
								.goreleaser.yml.tmpl
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										66
									
								
								.goreleaser.yml.tmpl
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,66 @@ | ||||
| project_name: traefik | ||||
|  | ||||
| dist: "./dist/[[ .GOOS ]]" | ||||
|  | ||||
| [[ if eq .GOOS "linux" ]] | ||||
| before: | ||||
|   hooks: | ||||
|     - go generate | ||||
| [[ end ]] | ||||
|  | ||||
| builds: | ||||
|   - binary: traefik | ||||
|  | ||||
|     main: ./cmd/traefik/ | ||||
|     env: | ||||
|       - CGO_ENABLED=0 | ||||
|     ldflags: | ||||
|       - -s -w -X github.com/traefik/traefik/v3/pkg/version.Version={{.Version}} -X github.com/traefik/traefik/v3/pkg/version.Codename={{.Env.CODENAME}} -X github.com/traefik/traefik/v3/pkg/version.BuildDate={{.Date}} | ||||
|     flags: | ||||
|       - -trimpath | ||||
|     goos: | ||||
|       - "[[ .GOOS ]]" | ||||
|     goarch: | ||||
|       - amd64 | ||||
|       - '386' | ||||
|       - arm | ||||
|       - arm64 | ||||
|       - ppc64le | ||||
|       - s390x | ||||
|       - riscv64 | ||||
|     goarm: | ||||
|       - '7' | ||||
|       - '6' | ||||
|     ignore: | ||||
|       - goos: darwin | ||||
|         goarch: '386' | ||||
|       - goos: openbsd | ||||
|         goarch: arm | ||||
|       - goos: openbsd | ||||
|         goarch: arm64 | ||||
|       - goos: freebsd | ||||
|         goarch: arm | ||||
|       - goos: freebsd | ||||
|         goarch: arm64 | ||||
|       - goos: windows | ||||
|         goarch: arm | ||||
|  | ||||
| changelog: | ||||
|   disable: true | ||||
|  | ||||
| archives: | ||||
|   - id: traefik | ||||
|     name_template: '{{ .ProjectName }}_v{{ .Version }}_{{ .Os }}_{{ .Arch }}{{ if .Arm }}v{{ .Arm }}{{ end }}' | ||||
|     format: tar.gz | ||||
|     format_overrides: | ||||
|       - goos: windows | ||||
|         format: zip | ||||
|     files: | ||||
|       - LICENSE.md | ||||
|       - CHANGELOG.md | ||||
|  | ||||
| checksum: | ||||
|   name_template: "{{ .ProjectName }}_v{{ .Version }}_checksums.txt" | ||||
|  | ||||
| release: | ||||
|   disable: true | ||||
| @@ -1,10 +0,0 @@ | ||||
| -   repo: git://github.com/pre-commit/pre-commit-hooks | ||||
|     sha: 44e1753f98b0da305332abe26856c3e621c5c439 | ||||
|     hooks: | ||||
|     -   id: detect-private-key | ||||
| -   repo: git://github.com/containous/pre-commit-hooks | ||||
|     sha: 35e641b5107671e94102b0ce909648559e568d61 | ||||
|     hooks: | ||||
|     -   id: goFmt | ||||
|     -   id: goLint | ||||
|     -   id: goErrcheck | ||||
							
								
								
									
										63
									
								
								.semaphore/semaphore.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										63
									
								
								.semaphore/semaphore.yml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,63 @@ | ||||
| version: v1.0 | ||||
| name: Traefik | ||||
| agent: | ||||
|   machine: | ||||
|     type: e1-standard-4 | ||||
|     os_image: ubuntu2004 | ||||
|  | ||||
| fail_fast: | ||||
|   stop: | ||||
|     when: "branch != 'master'" | ||||
|  | ||||
| auto_cancel: | ||||
|   queued: | ||||
|     when: "branch != 'master'" | ||||
|   running: | ||||
|     when: "branch != 'master'" | ||||
|  | ||||
| global_job_config: | ||||
|   prologue: | ||||
|     commands: | ||||
|       - curl -sSfL https://raw.githubusercontent.com/ldez/semgo/master/godownloader.sh | sudo sh -s -- -b "/usr/local/bin" | ||||
|       - sudo semgo go1.22 | ||||
|       - export "GOPATH=$(go env GOPATH)" | ||||
|       - export "SEMAPHORE_GIT_DIR=${GOPATH}/src/github.com/traefik/${SEMAPHORE_PROJECT_NAME}" | ||||
|       - export "PATH=${GOPATH}/bin:${PATH}" | ||||
|       - mkdir -vp "${SEMAPHORE_GIT_DIR}" "${GOPATH}/bin" | ||||
|       - export GOPROXY=https://proxy.golang.org,direct | ||||
|       - curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b "${GOPATH}/bin" v1.59.0 | ||||
|       - curl -sSfL https://gist.githubusercontent.com/traefiker/6d7ac019c11d011e4f131bb2cca8900e/raw/goreleaser.sh | bash -s -- -b "${GOPATH}/bin" | ||||
|       - checkout | ||||
|       - cache restore traefik-$(checksum go.sum) | ||||
|  | ||||
| blocks: | ||||
|   - name: Release | ||||
|     dependencies: [] | ||||
|     run: | ||||
|       when: "tag =~ '.*'" | ||||
|     task: | ||||
|       agent: | ||||
|         machine: | ||||
|           type: e1-standard-8 | ||||
|           os_image: ubuntu2004 | ||||
|       secrets: | ||||
|         - name: traefik | ||||
|       env_vars: | ||||
|         - name: GH_VERSION | ||||
|           value: 2.32.1 | ||||
|         - name: CODENAME | ||||
|           value: "comte" | ||||
|       prologue: | ||||
|         commands: | ||||
|           - export VERSION=${SEMAPHORE_GIT_TAG_NAME} | ||||
|           - curl -sSL -o /tmp/gh_${GH_VERSION}_linux_amd64.tar.gz https://github.com/cli/cli/releases/download/v${GH_VERSION}/gh_${GH_VERSION}_linux_amd64.tar.gz | ||||
|           - tar -zxvf /tmp/gh_${GH_VERSION}_linux_amd64.tar.gz -C /tmp | ||||
|           - sudo mv /tmp/gh_${GH_VERSION}_linux_amd64/bin/gh /usr/local/bin/gh | ||||
|           - sudo rm -rf ~/.phpbrew ~/.kerl ~/.sbt ~/.nvm ~/.npm ~/.kiex /usr/lib/jvm /opt/az /opt/firefox /usr/lib/google-cloud-sdk ~/.rbenv ~/.pip_download_cache # Remove unnecessary data. | ||||
|           - sudo service docker stop && sudo umount /var/lib/docker && sudo service docker start # Unmounts the docker disk and the whole system disk is usable. | ||||
|       jobs: | ||||
|         - name: Release | ||||
|           commands: | ||||
|             - make release-packages | ||||
|             - gh release create ${SEMAPHORE_GIT_TAG_NAME} ./dist/**/traefik*.{zip,tar.gz} ./dist/traefik*.{tar.gz,txt} --repo traefik/traefik --title ${SEMAPHORE_GIT_TAG_NAME} --notes ${SEMAPHORE_GIT_TAG_NAME} | ||||
|             - ./script/deploy.sh | ||||
| @@ -1,11 +0,0 @@ | ||||
| #!/usr/bin/env bash | ||||
| set -e | ||||
|  | ||||
| sudo -E apt-get -yq update | ||||
| sudo -E apt-get -yq --no-install-suggests --no-install-recommends --force-yes install docker-ce=${DOCKER_VERSION}* | ||||
| docker version | ||||
|  | ||||
| pip install --user -r requirements.txt | ||||
|  | ||||
| make pull-images | ||||
| ci_retry make validate | ||||
| @@ -1,6 +0,0 @@ | ||||
| #!/usr/bin/env bash | ||||
| set -e | ||||
|  | ||||
| make test-unit | ||||
| ci_retry make test-integration | ||||
| make -j${N_MAKE_JOBS} crossbinary-default-parallel | ||||
| @@ -1,37 +0,0 @@ | ||||
| #!/usr/bin/env bash | ||||
| set -e | ||||
|  | ||||
| export REPO='containous/traefik' | ||||
|  | ||||
| if VERSION=$(git describe --exact-match --abbrev=0 --tags); | ||||
| then | ||||
|   export VERSION | ||||
| else | ||||
|   export VERSION='' | ||||
| fi | ||||
|  | ||||
| export CODENAME=tetedemoine | ||||
|  | ||||
| export N_MAKE_JOBS=2 | ||||
|  | ||||
|  | ||||
| function ci_retry { | ||||
|  | ||||
|     local NRETRY=3 | ||||
|     local NSLEEP=5 | ||||
|     local n=0 | ||||
|  | ||||
|     until [ $n -ge $NRETRY ] | ||||
|     do | ||||
|         "$@" && break | ||||
|         n=$[$n+1] | ||||
|         echo "$@ failed, attempt ${n}/${NRETRY}" | ||||
|         sleep $NSLEEP | ||||
|     done | ||||
|  | ||||
|     [ $n -lt $NRETRY ] | ||||
|  | ||||
| } | ||||
|  | ||||
| export -f ci_retry | ||||
|  | ||||
							
								
								
									
										63
									
								
								.travis.yml
									
									
									
									
									
								
							
							
						
						
									
										63
									
								
								.travis.yml
									
									
									
									
									
								
							| @@ -1,63 +0,0 @@ | ||||
| sudo: required | ||||
| dist: trusty | ||||
|  | ||||
| git: | ||||
|   depth: false | ||||
|  | ||||
| services: | ||||
|   - docker | ||||
|  | ||||
| env: | ||||
|   global: | ||||
|     - REPO: $TRAVIS_REPO_SLUG | ||||
|     - VERSION: $TRAVIS_TAG | ||||
|     - CODENAME: tetedemoine | ||||
|     - N_MAKE_JOBS: 2 | ||||
|  | ||||
| script: | ||||
| - echo "Skipping tests... (Tests are executed on SemaphoreCI)" | ||||
|  | ||||
| before_deploy: | ||||
|   - > | ||||
|     if ! [ "$BEFORE_DEPLOY_RUN" ]; then | ||||
|       export BEFORE_DEPLOY_RUN=1; | ||||
|       sudo -E apt-get -yq update; | ||||
|       sudo -E apt-get -yq --no-install-suggests --no-install-recommends --force-yes install docker-ce=${DOCKER_VERSION}*; | ||||
|       docker version; | ||||
|       make image; | ||||
|       if [ "$TRAVIS_TAG" ]; then | ||||
|         make -j${N_MAKE_JOBS} crossbinary-parallel; | ||||
|         tar cfz dist/traefik-${VERSION}.src.tar.gz --exclude-vcs --exclude dist .; | ||||
|       fi; | ||||
|       curl -sI https://github.com/containous/structor/releases/latest | grep -Fi Location  | tr -d '\r' | sed "s/tag/download/g" | awk -F " " '{ print $2 "/structor_linux-amd64"}' | wget --output-document=$GOPATH/bin/structor -i -; | ||||
|       chmod +x $GOPATH/bin/structor; | ||||
|       structor -o containous -r traefik --dockerfile-url="https://raw.githubusercontent.com/containous/traefik/master/docs.Dockerfile" --menu.js-url="https://raw.githubusercontent.com/containous/structor/master/traefik-menu.js.gotmpl" --rqts-url="https://raw.githubusercontent.com/containous/structor/master/requirements-override.txt" --exp-branch=master --debug; | ||||
|     fi | ||||
| deploy: | ||||
|   - provider: releases | ||||
|     api_key: ${GITHUB_TOKEN} | ||||
|     file: dist/traefik* | ||||
|     skip_cleanup: true | ||||
|     file_glob: true | ||||
|     on: | ||||
|       repo: containous/traefik | ||||
|       tags: true | ||||
|   - provider: script | ||||
|     script: sh script/deploy.sh | ||||
|     skip_cleanup: true | ||||
|     on: | ||||
|       repo: containous/traefik | ||||
|       tags: true | ||||
|   - provider: script | ||||
|     script: sh script/deploy-docker.sh | ||||
|     skip_cleanup: true | ||||
|     on: | ||||
|       repo: containous/traefik | ||||
|   - provider: pages | ||||
|     edge: false | ||||
|     github_token: ${GITHUB_TOKEN} | ||||
|     local_dir: site | ||||
|     skip_cleanup: true | ||||
|     on: | ||||
|       repo: containous/traefik | ||||
|       all_branches: true | ||||
										
											Binary file not shown.
										
									
								
							
							
								
								
									
										9199
									
								
								CHANGELOG.md
									
									
									
									
									
								
							
							
						
						
									
										9199
									
								
								CHANGELOG.md
									
									
									
									
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							| @@ -2,17 +2,11 @@ | ||||
|  | ||||
| ## Our Pledge | ||||
|  | ||||
| In the interest of fostering an open and welcoming environment, we as | ||||
| contributors and maintainers pledge to making participation in our project and | ||||
| our community a harassment-free experience for everyone, regardless of age, body | ||||
| size, disability, ethnicity, gender identity and expression, level of experience, | ||||
| nationality, personal appearance, race, religion, or sexual identity and | ||||
| orientation. | ||||
| In the interest of fostering an open and welcoming environment, we as contributors and maintainers pledge to making participation in our project and our community a harassment-free experience for everyone, regardless of age, body size, disability, ethnicity, gender identity and expression, level of experience, nationality, personal appearance, race, religion, or sexual identity and orientation. | ||||
|  | ||||
| ## Our Standards | ||||
|  | ||||
| Examples of behavior that contributes to creating a positive environment | ||||
| include: | ||||
| Examples of behavior that contributes to creating a positive environment include: | ||||
|  | ||||
| * Using welcoming and inclusive language | ||||
| * Being respectful of differing viewpoints and experiences | ||||
| @@ -22,53 +16,52 @@ include: | ||||
|  | ||||
| Examples of unacceptable behavior by participants include: | ||||
|  | ||||
| * The use of sexualized language or imagery and unwelcome sexual attention or | ||||
| advances | ||||
| * The use of sexualized language or imagery and unwelcome sexual attention or advances | ||||
| * Trolling, insulting/derogatory comments, and personal or political attacks | ||||
| * Public or private harassment | ||||
| * Publishing others' private information, such as a physical or electronic | ||||
|   address, without explicit permission | ||||
| * Other conduct which could reasonably be considered inappropriate in a | ||||
|   professional setting | ||||
| * Publishing others' private information, such as a physical or electronic address, without explicit permission | ||||
| * Other conduct which could reasonably be considered inappropriate in a professional setting | ||||
|  | ||||
| ## Our Responsibilities | ||||
|  | ||||
| Project maintainers are responsible for clarifying the standards of acceptable | ||||
| behavior and are expected to take appropriate and fair corrective action in | ||||
| response to any instances of unacceptable behavior. | ||||
| Project maintainers are responsible for clarifying the standards of acceptable behavior and are expected to take appropriate and fair corrective action in response to any instances of unacceptable behavior. | ||||
|  | ||||
| Project maintainers have the right and responsibility to remove, edit, or | ||||
| reject comments, commits, code, wiki edits, issues, and other contributions | ||||
| that are not aligned to this Code of Conduct, or to ban temporarily or | ||||
| permanently any contributor for other behaviors that they deem inappropriate, | ||||
| threatening, offensive, or harmful. | ||||
| Project maintainers have the right and responsibility to remove, edit, or reject comments, commits, code, wiki edits, issues, and other contributions that are not aligned to this Code of Conduct, or to ban temporarily or permanently any contributor for other behaviors that they deem inappropriate, threatening, offensive, or harmful. | ||||
|  | ||||
| ## Scope | ||||
|  | ||||
| This Code of Conduct applies both within project spaces and in public spaces | ||||
| when an individual is representing the project or its community. Examples of | ||||
| representing a project or community include using an official project e-mail | ||||
| address, posting via an official social media account, or acting as an appointed | ||||
| representative at an online or offline event. Representation of a project may be | ||||
| further defined and clarified by project maintainers. | ||||
| This Code of Conduct applies both within project spaces and in public spaces when an individual is representing the project or our community. | ||||
|  | ||||
| Examples of representing a project or community include using an official project e-mail address, posting via an official social media account, or acting as an appointed representative at an online or offline event. | ||||
| Representation of a project may be further defined and clarified by project maintainers. | ||||
|  | ||||
| ## Enforcement | ||||
|  | ||||
| Instances of abusive, harassing, or otherwise unacceptable behavior may be | ||||
| reported by contacting the project team at contact@containo.us | ||||
| All complaints will be reviewed and investigated and will result in a response that | ||||
| is deemed necessary and appropriate to the circumstances. The project team is | ||||
| obligated to maintain confidentiality with regard to the reporter of an incident. | ||||
| Instances of abusive, harassing, or otherwise unacceptable behavior may be reported by contacting the project team at contact@traefik.io | ||||
|  | ||||
| All complaints will be reviewed and investigated and will result in a response that is deemed necessary and appropriate to the circumstances. | ||||
|  | ||||
| The project team is obligated to maintain confidentiality with regard to the reporter of an incident. | ||||
|  | ||||
| Further details of specific enforcement policies may be posted separately. | ||||
|  | ||||
| Project maintainers who do not follow or enforce the Code of Conduct in good | ||||
| faith may face temporary or permanent repercussions as determined by other | ||||
| members of the project's leadership. | ||||
| Project maintainers who do not follow or enforce the Code of Conduct in good faith may face temporary or permanent repercussions as determined by other members of the project's leadership. | ||||
|  | ||||
| When an inapropriate behavior is reported, maintainers will discuss on the Maintainer's Discord before marking the message as "abuse".  | ||||
| This conversation beforehand avoids one-sided decisions. | ||||
|  | ||||
| The first message will be edited and marked as abuse. | ||||
| The second edited message and marked as abuse results in a 7-day ban. | ||||
| The third edited message and marked as abuse results in a permanent ban. | ||||
|  | ||||
| The content of edited messages is: | ||||
| `Dear user, we want traefik to provide a welcoming and respectful environment. Your [comment/issue/PR] has been reported and marked as abuse according to our [Code of Conduct](./CODE_OF_CONDUCT.md). Thank you.` | ||||
|  | ||||
| The [report must be resolved](https://docs.github.com/en/communities/moderating-comments-and-conversations/managing-reported-content-in-your-organizations-repository#resolving-a-report) accordingly. | ||||
|  | ||||
| ## Attribution | ||||
|  | ||||
| This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 1.4, | ||||
| available at [http://contributor-covenant.org/version/1/4][version] | ||||
| This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 1.4, available at [http://contributor-covenant.org/version/1/4][version] | ||||
|  | ||||
| [homepage]: http://contributor-covenant.org | ||||
| [version]: http://contributor-covenant.org/version/1/4/ | ||||
|   | ||||
							
								
								
									
										263
									
								
								CONTRIBUTING.md
									
									
									
									
									
								
							
							
						
						
									
										263
									
								
								CONTRIBUTING.md
									
									
									
									
									
								
							| @@ -1,260 +1,11 @@ | ||||
| # Contributing | ||||
|  | ||||
| ## Building | ||||
| Here are some guidelines that should help to start contributing to the project. | ||||
|  | ||||
| You need either [Docker](https://github.com/docker/docker) and `make` (Method 1), or `go` (Method 2) in order to build Traefik. | ||||
| For changes to its dependencies, the `dep` dependency management tool is required. | ||||
| - [Submitting pull Requests](https://doc.traefik.io/traefik/contributing/submitting-pull-requests/) | ||||
| - [Submitting issues](https://doc.traefik.io/traefik/contributing/submitting-issues/) | ||||
| - [Submitting security issues](https://doc.traefik.io/traefik/contributing/submitting-security-issues/) | ||||
| - [Advocating for Traefik](https://doc.traefik.io/traefik/contributing/advocating/) | ||||
| - [Triage Process](https://github.com/traefik/contributors-guide/blob/master/issue_triage.md) | ||||
|  | ||||
| ### Method 1: Using `Docker` and `Makefile` | ||||
|  | ||||
| You need to run the `binary` target. This will create binaries for Linux platform in the `dist` folder. | ||||
|  | ||||
| ```bash | ||||
| $ make binary | ||||
| docker build -t "traefik-dev:no-more-godep-ever" -f build.Dockerfile . | ||||
| Sending build context to Docker daemon 295.3 MB | ||||
| Step 0 : FROM golang:1.10-alpine | ||||
|  ---> 8c6473912976 | ||||
| Step 1 : RUN go get github.com/golang/dep/cmd/dep | ||||
| [...] | ||||
| docker run --rm  -v "/var/run/docker.sock:/var/run/docker.sock" -it -e OS_ARCH_ARG -e OS_PLATFORM_ARG -e TESTFLAGS -v "/home/user/go/src/github.com/containous/traefik/"dist":/go/src/github.com/containous/traefik/"dist"" "traefik-dev:no-more-godep-ever" ./script/make.sh generate binary | ||||
| ---> Making bundle: generate (in .) | ||||
| removed 'gen.go' | ||||
|  | ||||
| ---> Making bundle: binary (in .) | ||||
|  | ||||
| $ ls dist/ | ||||
| traefik* | ||||
| ``` | ||||
|  | ||||
| ### Method 2: Using `go` | ||||
|  | ||||
| ##### Setting up your `go` environment | ||||
|  | ||||
| - You need `go` v1.9+ | ||||
| - It is recommended you clone Træfik into a directory like `~/go/src/github.com/containous/traefik` (This is the official golang workspace hierarchy, and will allow dependencies to resolve properly) | ||||
| - Set your `GOPATH` and `PATH` variable to be set to `~/go` via: | ||||
|  | ||||
| ```bash | ||||
| export GOPATH=~/go | ||||
| export PATH=$PATH:$GOPATH/bin | ||||
| ``` | ||||
|  | ||||
| > Note: You will want to add those 2 export lines to your `.bashrc` or `.bash_profile` | ||||
|  | ||||
| - Verify your environment is setup properly by running `$ go env`.  Depending on your OS and environment you should see output similar to: | ||||
|  | ||||
| ```bash | ||||
| GOARCH="amd64" | ||||
| GOBIN="" | ||||
| GOEXE="" | ||||
| GOHOSTARCH="amd64" | ||||
| GOHOSTOS="linux" | ||||
| GOOS="linux" | ||||
| GOPATH="/home/<yourusername>/go" | ||||
| GORACE="" | ||||
| ## more go env's will be listed | ||||
| ``` | ||||
|  | ||||
| ##### Build Træfik | ||||
|  | ||||
| Once your environment is set up and the Træfik repository cloned you can build Træfik. You need get `go-bindata` once to be able to use `go generate` command as part of the build.  The steps to build are: | ||||
|  | ||||
| ```bash | ||||
| cd ~/go/src/github.com/containous/traefik | ||||
|  | ||||
| # Get go-bindata. Please note, the ellipses are required | ||||
| go get github.com/containous/go-bindata/... | ||||
|  | ||||
| # Start build | ||||
|  | ||||
| # generate | ||||
| # (required to merge non-code components into the final binary, such as the web dashboard and provider's Go templates) | ||||
| go generate | ||||
|  | ||||
| # Standard go build | ||||
| go build ./cmd/traefik | ||||
| # run other commands like tests | ||||
| ``` | ||||
|  | ||||
| You will find the Træfik executable in the `~/go/src/github.com/containous/traefik` folder as `traefik`. | ||||
|  | ||||
| ### Updating the templates | ||||
|  | ||||
| If you happen to update the provider templates (in `/templates`), you need to run `go generate` to update the `autogen` package. | ||||
|  | ||||
| ### Setting up dependency management | ||||
|  | ||||
| [dep](https://github.com/golang/dep) is not required for building; however, it is necessary to modify dependencies (i.e., add, update, or remove third-party packages) | ||||
|  | ||||
| You need to use [dep](https://github.com/golang/dep) >= O.4.1. | ||||
|  | ||||
| If you want to add a dependency, use `dep ensure -add` to have [dep](https://github.com/golang/dep) put it into the vendor folder and update the dep manifest/lock files (`Gopkg.toml` and `Gopkg.lock`, respectively). | ||||
|  | ||||
| A following `make dep-prune` run should be triggered to trim down the size of the vendor folder. | ||||
| The final result must be committed into VCS. | ||||
|  | ||||
| Here's a full example using dep to add a new dependency: | ||||
|  | ||||
| ```bash | ||||
| # install the new main dependency github.com/foo/bar and minimize vendor size | ||||
| $ dep ensure -add github.com/foo/bar | ||||
| # generate (Only required to integrate other components such as web dashboard) | ||||
| $ go generate | ||||
| # Standard go build | ||||
| $ go build ./cmd/traefik | ||||
| # run other commands like tests | ||||
| ``` | ||||
|  | ||||
| ### Tests | ||||
|  | ||||
| #### Method 1: `Docker` and `make` | ||||
|  | ||||
| You can run unit tests using the `test-unit` target and the | ||||
| integration test using the `test-integration` target. | ||||
|  | ||||
| ```bash | ||||
| $ make test-unit | ||||
| docker build -t "traefik-dev:your-feature-branch" -f build.Dockerfile . | ||||
| # […] | ||||
| docker run --rm -it -e OS_ARCH_ARG -e OS_PLATFORM_ARG -e TESTFLAGS -v "/home/user/go/src/github/containous/traefik/dist:/go/src/github.com/containous/traefik/dist" "traefik-dev:your-feature-branch" ./script/make.sh generate test-unit | ||||
| ---> Making bundle: generate (in .) | ||||
| removed 'gen.go' | ||||
|  | ||||
| ---> Making bundle: test-unit (in .) | ||||
| + go test -cover -coverprofile=cover.out . | ||||
| ok      github.com/containous/traefik   0.005s  coverage: 4.1% of statements | ||||
|  | ||||
| Test success | ||||
| ``` | ||||
|  | ||||
| For development purposes, you can specify which tests to run by using: | ||||
|  | ||||
| ```bash | ||||
| # Run every tests in the MyTest suite | ||||
| TESTFLAGS="-check.f MyTestSuite" make test-integration | ||||
|  | ||||
| # Run the test "MyTest" in the MyTest suite | ||||
| TESTFLAGS="-check.f MyTestSuite.MyTest" make test-integration | ||||
|  | ||||
| # Run every tests starting with "My", in the MyTest suite | ||||
| TESTFLAGS="-check.f MyTestSuite.My" make test-integration | ||||
|  | ||||
| # Run every tests ending with "Test", in the MyTest suite | ||||
| TESTFLAGS="-check.f MyTestSuite.*Test" make test-integration | ||||
| ``` | ||||
|  | ||||
| More: https://labix.org/gocheck | ||||
|  | ||||
| #### Method 2: `go` | ||||
|  | ||||
| Unit tests can be run from the cloned directory by `$ go test ./...` which should return `ok` similar to: | ||||
|  | ||||
| ``` | ||||
| ok      _/home/user/go/src/github/containous/traefik    0.004s | ||||
| ``` | ||||
|  | ||||
| Integration tests must be run from the `integration/` directory and require the `-integration` switch to be passed like this: `$ cd integration && go test -integration ./...`. | ||||
|  | ||||
| ## Documentation | ||||
|  | ||||
| The [documentation site](http://docs.traefik.io/) is built with [mkdocs](http://mkdocs.org/) | ||||
|  | ||||
| ### Method 1: `Docker` and `make` | ||||
|  | ||||
| You can test documentation using the `docs` target. | ||||
|  | ||||
| ```bash | ||||
| $ make docs | ||||
| docker build -t traefik-docs -f docs.Dockerfile . | ||||
| # […] | ||||
| docker run  --rm -v /home/user/go/github/containous/traefik:/mkdocs -p 8000:8000 traefik-docs mkdocs serve | ||||
| # […] | ||||
| [I 170828 20:47:48 server:283] Serving on http://0.0.0.0:8000 | ||||
| [I 170828 20:47:48 handlers:60] Start watching changes | ||||
| [I 170828 20:47:48 handlers:62] Start detecting changes | ||||
| ``` | ||||
|  | ||||
| And go to [http://127.0.0.1:8000](http://127.0.0.1:8000). | ||||
|  | ||||
| ### Method 2: `mkdocs` | ||||
|  | ||||
| First make sure you have python and pip installed | ||||
|  | ||||
| ```shell | ||||
| $ python --version | ||||
| Python 2.7.2 | ||||
| $ pip --version | ||||
| pip 1.5.2 | ||||
| ``` | ||||
|  | ||||
| Then install mkdocs with pip | ||||
|  | ||||
| ```shell | ||||
| pip install --user -r requirements.txt | ||||
| ``` | ||||
|  | ||||
| To test documentation locally run `mkdocs serve` in the root directory, this should start a server locally to preview your changes. | ||||
|  | ||||
| ```shell | ||||
| $ mkdocs serve | ||||
| INFO    -  Building documentation... | ||||
| WARNING -  Config value: 'theme'. Warning: The theme 'united' will be removed in an upcoming MkDocs release. See http://www.mkdocs.org/about/release-notes/ for more details | ||||
| INFO    -  Cleaning site directory | ||||
| [I 160505 22:31:24 server:281] Serving on http://127.0.0.1:8000 | ||||
| [I 160505 22:31:24 handlers:59] Start watching changes | ||||
| [I 160505 22:31:24 handlers:61] Start detecting changes | ||||
| ``` | ||||
|  | ||||
|  | ||||
| ## How to Write a Good Issue | ||||
|  | ||||
| Please keep in mind that the GitHub issue tracker is not intended as a general support forum, but for reporting bugs and feature requests. | ||||
|  | ||||
| For end-user related support questions, refer to one of the following: | ||||
| - the Traefik community Slack channel: [](https://traefik.herokuapp.com) | ||||
| - [Stack Overflow](https://stackoverflow.com/questions/tagged/traefik) (using the `traefik` tag) | ||||
|  | ||||
| ### Title | ||||
|  | ||||
| The title must be short and descriptive. (~60 characters) | ||||
|  | ||||
| ### Description | ||||
|  | ||||
| - Respect the issue template as much as possible. [template](.github/ISSUE_TEMPLATE.md) | ||||
| - If it's possible use the command `traefik bug`. See https://www.youtube.com/watch?v=Lyz62L8m93I. | ||||
| - Explain the conditions which led you to write this issue: the context. | ||||
| - The context should lead to something, an idea or a problem that you’re facing. | ||||
| - Remain clear and concise. | ||||
| - Format your messages to help the reader focus on what matters and understand the structure of your message, use [Markdown syntax](https://help.github.com/articles/github-flavored-markdown) | ||||
|  | ||||
|  | ||||
| ## How to Write a Good Pull Request | ||||
|  | ||||
| ### Title | ||||
|  | ||||
| The title must be short and descriptive. (~60 characters) | ||||
|  | ||||
| ### Description | ||||
|  | ||||
| - Respect the pull request template as much as possible. [template](.github/PULL_REQUEST_TEMPLATE.md) | ||||
| - Explain the conditions which led you to write this PR: the context. | ||||
| - The context should lead to something, an idea or a problem that you’re facing. | ||||
| - Remain clear and concise. | ||||
| - Format your messages to help the reader focus on what matters and understand the structure of your message, use [Markdown syntax](https://help.github.com/articles/github-flavored-markdown) | ||||
|  | ||||
| ### Content | ||||
|  | ||||
| - Make it small. | ||||
| - Do only one thing. | ||||
| - Write useful descriptions and titles. | ||||
| - Avoid re-formatting. | ||||
| - Make sure the code builds. | ||||
| - Make sure all tests pass. | ||||
| - Add tests. | ||||
| - Address review comments in terms of additional commits. | ||||
| - Do not amend/squash existing ones unless the PR is trivial. | ||||
| - If a PR involves changes to third-party dependencies, the commits pertaining to the vendor folder and the manifest/lock file(s) should be committed separated. | ||||
|  | ||||
|  | ||||
| Read [10 tips for better pull requests](http://blog.ploeh.dk/2015/01/15/10-tips-for-better-pull-requests/). | ||||
| If you are willing to become a maintainer of the project, please take a look at the [maintainers guidelines](docs/content/contributing/maintainers-guidelines.md). | ||||
|   | ||||
							
								
								
									
										13
									
								
								Dockerfile
									
									
									
									
									
								
							
							
						
						
									
										13
									
								
								Dockerfile
									
									
									
									
									
								
							| @@ -1,5 +1,12 @@ | ||||
| FROM scratch | ||||
| COPY script/ca-certificates.crt /etc/ssl/certs/ | ||||
| COPY dist/traefik / | ||||
| # syntax=docker/dockerfile:1.2 | ||||
| FROM alpine:3.20 | ||||
|  | ||||
| RUN apk add --no-cache --no-progress ca-certificates tzdata | ||||
|  | ||||
| ARG TARGETPLATFORM | ||||
| COPY ./dist/$TARGETPLATFORM/traefik / | ||||
|  | ||||
| EXPOSE 80 | ||||
| VOLUME ["/tmp"] | ||||
|  | ||||
| ENTRYPOINT ["/traefik"] | ||||
|   | ||||
							
								
								
									
										1649
									
								
								Gopkg.lock
									
									
									
										generated
									
									
									
								
							
							
						
						
									
										1649
									
								
								Gopkg.lock
									
									
									
										generated
									
									
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										257
									
								
								Gopkg.toml
									
									
									
									
									
								
							
							
						
						
									
										257
									
								
								Gopkg.toml
									
									
									
									
									
								
							| @@ -1,257 +0,0 @@ | ||||
| # Gopkg.toml example | ||||
| # | ||||
| # Refer to https://github.com/golang/dep/blob/master/docs/Gopkg.toml.md | ||||
| # for detailed Gopkg.toml documentation. | ||||
| # | ||||
| # required = ["github.com/user/thing/cmd/thing"] | ||||
| # ignored = ["github.com/user/project/pkgX", "bitbucket.org/user/project/pkgA/pkgY"] | ||||
| # | ||||
| # [[constraint]] | ||||
| #   name = "github.com/user/project" | ||||
| #   version = "1.0.0" | ||||
| # | ||||
| # [[constraint]] | ||||
| #   name = "github.com/user/project2" | ||||
| #   branch = "dev" | ||||
| #   source = "github.com/myfork/project2" | ||||
| # | ||||
| # [[override]] | ||||
| #  name = "github.com/x/y" | ||||
| #  version = "2.4.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/ArthurHlt/go-eureka-client" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/BurntSushi/toml" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/BurntSushi/ty" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/NYTimes/gziphandler" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "containous-fork" | ||||
|   name = "github.com/abbot/go-http-auth" | ||||
|   source = "github.com/containous/go-http-auth" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/armon/go-proxyproto" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/aws/aws-sdk-go" | ||||
|   version = "1.13.1" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/cenk/backoff" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/containous/flaeg" | ||||
|   version = "1.0.1" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/containous/mux" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/containous/staert" | ||||
|   version = "3.1.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/containous/traefik-extra-service-fabric" | ||||
|   version = "1.1.1" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/coreos/go-systemd" | ||||
|   version = "14.0.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/docker/leadership" | ||||
|   source = "github.com/containous/leadership" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/eapache/channels" | ||||
|   version = "1.1.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/elazarl/go-bindata-assetfs" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "fork-containous" | ||||
|   name = "github.com/go-check/check" | ||||
|   source = "github.com/containous/check" | ||||
|  | ||||
| [[override]] | ||||
|   branch = "fork-containous" | ||||
|   name = "github.com/go-check/check" | ||||
|   source = "github.com/containous/check" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/go-kit/kit" | ||||
|   version = "0.3.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/gorilla/websocket" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/hashicorp/consul" | ||||
|   version = "1.0.6" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/influxdata/influxdb" | ||||
|   version = "1.3.7" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/jjcollinge/servicefabric" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/abronan/valkeyrie" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/mesosphere/mesos-dns" | ||||
|   source = "https://github.com/containous/mesos-dns.git" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/mitchellh/copystructure" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/mitchellh/hashstructure" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/mitchellh/mapstructure" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/opentracing/opentracing-go" | ||||
|   version = "1.0.2" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "containous-fork" | ||||
|   name = "github.com/rancher/go-rancher-metadata" | ||||
|   source = "github.com/containous/go-rancher-metadata" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/ryanuber/go-glob" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/satori/go.uuid" | ||||
|   version = "1.1.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/stvp/go-udp-testing" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/stretchr/testify" | ||||
|   version = "1.2.1" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/uber/jaeger-client-go" | ||||
|   version = "2.9.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/uber/jaeger-lib" | ||||
|   version = "1.1.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "v1" | ||||
|   name = "github.com/unrolled/secure" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "github.com/vdemeester/shakers" | ||||
|   version = "0.1.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/vulcand/oxy" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "acmev2" | ||||
|   name = "github.com/xenolf/lego" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "google.golang.org/grpc" | ||||
|   version = "1.5.2" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "gopkg.in/fsnotify.v1" | ||||
|   source = "github.com/fsnotify/fsnotify" | ||||
|   version = "1.4.2" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "k8s.io/client-go" | ||||
|   version = "6.0.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "k8s.io/api" | ||||
|   version = "kubernetes-1.9.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   name = "k8s.io/apimachinery" | ||||
|   version = "kubernetes-1.9.0" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/libkermit/docker" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/libkermit/docker-check" | ||||
|  | ||||
| [[constraint]] | ||||
|   branch = "master" | ||||
|   name = "github.com/libkermit/compose" | ||||
|  | ||||
| [[constraint]] | ||||
|  name = "github.com/docker/docker" | ||||
|  revision = "7848b8beb9d38a98a78b75f78e05f8d2255f9dfe" | ||||
|  | ||||
| [[override]] | ||||
|  name = "github.com/docker/docker" | ||||
|  revision = "7848b8beb9d38a98a78b75f78e05f8d2255f9dfe" | ||||
|  | ||||
| [[override]] | ||||
|  name = "github.com/docker/cli" | ||||
|  revision = "6b63d7b96a41055baddc3fa71f381c7f60bd5d8e" | ||||
|  | ||||
| [[override]] | ||||
|  name = "github.com/docker/distribution" | ||||
|  revision = "edc3ab29cdff8694dd6feb85cfeb4b5f1b38ed9c" | ||||
|  | ||||
| [[override]] | ||||
|   branch = "master" | ||||
|   name = "github.com/docker/libcompose" | ||||
|  | ||||
| [[override]] | ||||
|   name = "github.com/Nvveen/Gotty" | ||||
|   revision = "a8b993ba6abdb0e0c12b0125c603323a71c7790c" | ||||
|   source = "github.com/ijc25/Gotty" | ||||
|  | ||||
| [[override]] | ||||
|   # ALWAYS keep this override | ||||
|   name = "github.com/mailgun/timetools" | ||||
|   revision = "7e6055773c5137efbeb3bd2410d705fe10ab6bfd" | ||||
|  | ||||
| [[override]] | ||||
|   branch = "master" | ||||
|   name = "github.com/miekg/dns" | ||||
|  | ||||
| [prune] | ||||
|   non-go = true | ||||
|   go-tests = true | ||||
|   unused-packages = true | ||||
| @@ -1,6 +1,6 @@ | ||||
| The MIT License (MIT) | ||||
|  | ||||
| Copyright (c) 2016-2018 Containous SAS | ||||
| Copyright (c) 2016-2020 Containous SAS; 2020-2024 Traefik Labs | ||||
|  | ||||
| Permission is hereby granted, free of charge, to any person obtaining a copy | ||||
| of this software and associated documentation files (the "Software"), to deal | ||||
|   | ||||
							
								
								
									
										154
									
								
								MAINTAINER.md
									
									
									
									
									
								
							
							
						
						
									
										154
									
								
								MAINTAINER.md
									
									
									
									
									
								
							| @@ -1,154 +0,0 @@ | ||||
| # Maintainers | ||||
|  | ||||
| ## The team | ||||
|  | ||||
| * Emile Vauge [@emilevauge](https://github.com/emilevauge) | ||||
| * Vincent Demeester [@vdemeester](https://github.com/vdemeester) | ||||
| * Ed Robinson [@errm](https://github.com/errm) | ||||
| * Daniel Tomcej [@dtomcej](https://github.com/dtomcej) | ||||
| * Manuel Zapf [@SantoDE](https://github.com/SantoDE) | ||||
| * Timo Reimann [@timoreimann](https://github.com/timoreimann) | ||||
| * Ludovic Fernandez [@ldez](https://github.com/ldez) | ||||
| * Julien Salleyron [@juliens](https://github.com/juliens) | ||||
| * Nicolas Mengin [@nmengin](https://github.com/nmengin) | ||||
| * Marco Jantke [@marco-jantke](https://github.com/marco-jantke) | ||||
| * Michaël Matur [@mmatur](https://github.com/mmatur) | ||||
|  | ||||
|  | ||||
| ## PR review process: | ||||
|  | ||||
| * The status `needs-design-review` is only used in complex/heavy/tricky PRs. | ||||
| * From `1` to `2`: 1 design LGTM in comment, by a senior maintainer, if needed. | ||||
| * From `2` to `3`: 3 LGTM by any maintainer. | ||||
| * If needed, a specific maintainer familiar with a particular domain can be requested for the review. | ||||
|  | ||||
| We use [PRM](https://github.com/ldez/prm) to manage locally pull requests. | ||||
|  | ||||
|  | ||||
| ## Bots | ||||
|  | ||||
| ### [Myrmica Lobicornis](https://github.com/containous/lobicornis/) | ||||
|  | ||||
| **Update and Merge Pull Request** | ||||
|  | ||||
| The maintainer giving the final LGTM must add the `status/3-needs-merge` label to trigger the merge bot. | ||||
|  | ||||
| By default, a squash-rebase merge will be carried out. | ||||
| If you want to preserve commits you must add `bot/merge-method-rebase` before `status/3-needs-merge`. | ||||
|  | ||||
| The status `status/4-merge-in-progress` is only for the bot. | ||||
|  | ||||
| If the bot is not able to perform the merge, the label `bot/need-human-merge` is added.   | ||||
| In this case you must solve conflicts/CI/... and after you only need to remove `bot/need-human-merge`. | ||||
|  | ||||
| A maintainer can add `bot/no-merge` on a PR if he want (temporarily) prevent a merge by the bot. | ||||
|  | ||||
| `bot/light-review` can be used to decrease required LGTM from 3 to 1 when: | ||||
|  | ||||
| - vendor updates from previously reviewed PRs | ||||
| - merges branches into master | ||||
| - prepare release | ||||
|  | ||||
|  | ||||
| ### [Myrmica Bibikoffi](https://github.com/containous/bibikoffi/) | ||||
|  | ||||
| * closes stale issues [cron] | ||||
|     * use some criterion as number of days between creation, last update, labels, ... | ||||
|  | ||||
|  | ||||
| ### [Myrmica Aloba](https://github.com/containous/aloba) | ||||
|  | ||||
| **Manage GitHub labels** | ||||
|  | ||||
| * Add labels on new PR [GitHub WebHook] | ||||
| * Add milestone to a new PR based on a branch version (1.4, 1.3, ...) [GitHub WebHook] | ||||
| * Add and remove `contributor/waiting-for-corrections` label when a review request changes [GitHub WebHook] | ||||
| * Weekly report of PR status on Slack (CaptainPR) [cron] | ||||
|  | ||||
|  | ||||
| ## Labels | ||||
|  | ||||
| If we open/look an issue/PR, we must add a `kind/*`, an `area/*` and a `status/*`. | ||||
|  | ||||
| ### Contributor | ||||
|  | ||||
| * `contributor/need-more-information`: we need more information from the contributor in order to analyze a problem. | ||||
| * `contributor/waiting-for-feedback`: we need the contributor to give us feedback. | ||||
| * `contributor/waiting-for-corrections`: we need the contributor to take actions in order to move forward with a PR. **(only for PR)** _[bot, humans]_ | ||||
| * `contributor/needs-resolve-conflicts`: use it only when there is some conflicts (and an automatic rebase is not possible). **(only for PR)** _[bot, humans]_ | ||||
|  | ||||
| ### Kind | ||||
|  | ||||
| * `kind/enhancement`: a new or improved feature. | ||||
| * `kind/question`: It's a question. **(only for issue)** | ||||
| * `kind/proposal`: proposal PR/issues need a public debate. | ||||
|   * _Proposal issues_ are design proposal that need to be refined with multiple contributors. | ||||
|   * _Proposal PRs_ are technical prototypes that need to be refined with multiple contributors. | ||||
|  | ||||
| * `kind/bug/possible`: if we need to analyze to understand if it's a bug or not. **(only for issues)** | ||||
| * `kind/bug/confirmed`: we are sure, it's a bug. **(only for issues)** | ||||
| * `kind/bug/fix`: it's a bug fix. **(only for PR)** | ||||
|  | ||||
| ### Resolution | ||||
|  | ||||
| * `resolution/duplicate`: it's a duplicate issue/PR. | ||||
| * `resolution/declined`: Rule #1 of open-source: no is temporary, yes is forever. | ||||
| * `WIP`: Work In Progress. **(only for PR)** | ||||
|  | ||||
| ### Platform | ||||
|  | ||||
| * `platform/windows`: Windows related. | ||||
|  | ||||
| ### Area | ||||
|  | ||||
| * `area/acme`: ACME related. | ||||
| * `area/api`: Traefik API related. | ||||
| * `area/authentication`: Authentication related. | ||||
| * `area/cluster`: Traefik clustering related. | ||||
| * `area/documentation`: regards improving/adding documentation. | ||||
| * `area/infrastructure`: related to CI or Traefik building scripts. | ||||
| * `area/healthcheck`: Health-check related. | ||||
| * `area/logs`: Traefik logs related. | ||||
| * `area/middleware`: Middleware related. | ||||
| * `area/middleware/metrics`: Metrics related. (Prometheus, StatsD, ...) | ||||
| * `area/oxy`: Oxy related. | ||||
| * `area/provider`: related to all providers. | ||||
| * `area/provider/boltdb`: Boltd DB related. | ||||
| * `area/provider/consul`: Consul related. | ||||
| * `area/provider/docker`: Docker and Swarm related. | ||||
| * `area/provider/ecs`: ECS related. | ||||
| * `area/provider/etcd`: Etcd related. | ||||
| * `area/provider/eureka`: Eureka related. | ||||
| * `area/provider/file`: file provider related. | ||||
| * `area/provider/k8s`: Kubernetes related. | ||||
| * `area/provider/marathon`: Marathon related. | ||||
| * `area/provider/mesos`: Mesos related. | ||||
| * `area/provider/rancher`: Rancher related. | ||||
| * `area/provider/zk`: Zoo Keeper related. | ||||
| * `area/sticky-session`: Sticky session related. | ||||
| * `area/tls`: TLS related. | ||||
| * `area/websocket`: WebSocket related. | ||||
| * `area/webui`: Web UI related. | ||||
|  | ||||
| ### Priority | ||||
|  | ||||
| * `priority/P0`: needs hot fix. **(only for issue)** | ||||
| * `priority/P1`: need to be fixed in next release. **(only for issue)** | ||||
| * `priority/P2`: need to be fixed in the future. **(only for issue)** | ||||
| * `priority/P3`: maybe. **(only for issue)** | ||||
|  | ||||
| ### PR size | ||||
|  | ||||
| * `size/S`: small PR. **(only for PR)** _[bot only]_ | ||||
| * `size/M`: medium PR. **(only for PR)** _[bot only]_ | ||||
| * `size/L`: Large PR. **(only for PR)** _[bot only]_ | ||||
|  | ||||
| ### Status - Workflow | ||||
|  | ||||
| The `status/*` labels represent the desired state in the workflow. | ||||
|  | ||||
| * `status/0-needs-triage`: all new issue or PR have this status. _[bot only]_ | ||||
| * `status/1-needs-design-review`: need a design review. **(only for PR)** | ||||
| * `status/2-needs-review`: need a code/documentation review. **(only for PR)** | ||||
| * `status/3-needs-merge`: ready to merge. **(only for PR)** | ||||
| * `status/4-merge-in-progress`: merge in progress. _[bot only]_ | ||||
							
								
								
									
										293
									
								
								Makefile
									
									
									
									
									
								
							
							
						
						
									
										293
									
								
								Makefile
									
									
									
									
									
								
							| @@ -1,138 +1,205 @@ | ||||
| .PHONY: all | ||||
|  | ||||
| TRAEFIK_ENVS := \ | ||||
| 	-e OS_ARCH_ARG \ | ||||
| 	-e OS_PLATFORM_ARG \ | ||||
| 	-e TESTFLAGS \ | ||||
| 	-e VERBOSE \ | ||||
| 	-e VERSION \ | ||||
| 	-e CODENAME \ | ||||
| 	-e TESTDIRS \ | ||||
| 	-e CI \ | ||||
| 	-e CONTAINER=DOCKER		# Indicator for integration tests that we are running inside a container. | ||||
|  | ||||
| SRCS = $(shell git ls-files '*.go' | grep -v '^vendor/') | ||||
|  | ||||
| BIND_DIR := "dist" | ||||
| TRAEFIK_MOUNT := -v "$(CURDIR)/$(BIND_DIR):/go/src/github.com/containous/traefik/$(BIND_DIR)" | ||||
| TAG_NAME := $(shell git tag -l --contains HEAD) | ||||
| SHA := $(shell git rev-parse HEAD) | ||||
| VERSION_GIT := $(if $(TAG_NAME),$(TAG_NAME),$(SHA)) | ||||
| VERSION := $(if $(VERSION),$(VERSION),$(VERSION_GIT)) | ||||
|  | ||||
| GIT_BRANCH := $(subst heads/,,$(shell git rev-parse --abbrev-ref HEAD 2>/dev/null)) | ||||
| TRAEFIK_DEV_IMAGE := traefik-dev$(if $(GIT_BRANCH),:$(subst /,-,$(GIT_BRANCH))) | ||||
|  | ||||
| REPONAME := $(shell echo $(REPO) | tr '[:upper:]' '[:lower:]') | ||||
| TRAEFIK_IMAGE := $(if $(REPONAME),$(REPONAME),"containous/traefik") | ||||
| INTEGRATION_OPTS := $(if $(MAKE_DOCKER_HOST),-e "DOCKER_HOST=$(MAKE_DOCKER_HOST)", -e "TEST_CONTAINER=1" -v "/var/run/docker.sock:/var/run/docker.sock") | ||||
| TRAEFIK_DOC_IMAGE := traefik-docs | ||||
| BIN_NAME := traefik | ||||
| CODENAME ?= cheddar | ||||
|  | ||||
| DOCKER_BUILD_ARGS := $(if $(DOCKER_VERSION), "--build-arg=DOCKER_VERSION=$(DOCKER_VERSION)",) | ||||
| DOCKER_RUN_OPTS := $(TRAEFIK_ENVS) $(TRAEFIK_MOUNT) "$(TRAEFIK_DEV_IMAGE)" | ||||
| DOCKER_RUN_TRAEFIK := docker run $(INTEGRATION_OPTS) -it $(DOCKER_RUN_OPTS) | ||||
| DOCKER_RUN_TRAEFIK_NOTTY := docker run $(INTEGRATION_OPTS) -i $(DOCKER_RUN_OPTS) | ||||
| DOCKER_RUN_DOC_PORT := 8000 | ||||
| DOCKER_RUN_DOC_MOUNT := -v $(CURDIR):/mkdocs | ||||
| DOCKER_RUN_DOC_OPTS := --rm $(DOCKER_RUN_DOC_MOUNT) -p $(DOCKER_RUN_DOC_PORT):8000 | ||||
| DATE := $(shell date -u '+%Y-%m-%d_%I:%M:%S%p') | ||||
|  | ||||
| # Default build target | ||||
| GOOS := $(shell go env GOOS) | ||||
| GOARCH := $(shell go env GOARCH) | ||||
|  | ||||
| print-%: ; @echo $*=$($*) | ||||
| LINT_EXECUTABLES = misspell shellcheck | ||||
|  | ||||
| default: binary | ||||
| DOCKER_BUILD_PLATFORMS ?= linux/amd64,linux/arm64 | ||||
|  | ||||
| all: generate-webui build ## validate all checks, build linux binary, run all tests\ncross non-linux binaries | ||||
| 	$(DOCKER_RUN_TRAEFIK) ./script/make.sh | ||||
| .PHONY: default | ||||
| #? default: Run `make generate` and `make binary` | ||||
| default: generate binary | ||||
|  | ||||
| binary: generate-webui build ## build the linux binary | ||||
| 	$(DOCKER_RUN_TRAEFIK) ./script/make.sh generate binary | ||||
| #? dist: Create the "dist" directory | ||||
| dist: | ||||
| 	mkdir -p dist | ||||
|  | ||||
| crossbinary: generate-webui build ## cross build the non-linux binaries | ||||
| 	$(DOCKER_RUN_TRAEFIK) ./script/make.sh generate crossbinary | ||||
|  | ||||
| crossbinary-parallel: | ||||
| 	$(MAKE) generate-webui | ||||
| 	$(MAKE) build crossbinary-default crossbinary-others | ||||
|  | ||||
| crossbinary-default: generate-webui build | ||||
| 	$(DOCKER_RUN_TRAEFIK_NOTTY) ./script/make.sh generate crossbinary-default | ||||
|  | ||||
| crossbinary-default-parallel: | ||||
| 	$(MAKE) generate-webui | ||||
| 	$(MAKE) build crossbinary-default | ||||
|  | ||||
| crossbinary-others: generate-webui build | ||||
| 	$(DOCKER_RUN_TRAEFIK_NOTTY) ./script/make.sh generate crossbinary-others | ||||
|  | ||||
| crossbinary-others-parallel: | ||||
| 	$(MAKE) generate-webui | ||||
| 	$(MAKE) build crossbinary-others | ||||
|  | ||||
| test: build ## run the unit and integration tests | ||||
| 	$(DOCKER_RUN_TRAEFIK) ./script/make.sh generate test-unit binary test-integration | ||||
|  | ||||
| test-unit: build ## run the unit tests | ||||
| 	$(DOCKER_RUN_TRAEFIK) ./script/make.sh generate test-unit | ||||
|  | ||||
| test-integration: build ## run the integration tests | ||||
| 	$(DOCKER_RUN_TRAEFIK) ./script/make.sh generate binary test-integration | ||||
| 	TEST_HOST=1 ./script/make.sh test-integration | ||||
|  | ||||
| validate: build  ## validate code, vendor and autogen | ||||
| 	$(DOCKER_RUN_TRAEFIK) ./script/make.sh validate-gofmt validate-govet validate-golint validate-misspell validate-vendor validate-autogen | ||||
|  | ||||
| build: dist | ||||
| 	docker build $(DOCKER_BUILD_ARGS) -t "$(TRAEFIK_DEV_IMAGE)" -f build.Dockerfile . | ||||
|  | ||||
| build-webui: | ||||
| .PHONY: build-webui-image | ||||
| #? build-webui-image: Build WebUI Docker image | ||||
| build-webui-image: | ||||
| 	docker build -t traefik-webui -f webui/Dockerfile webui | ||||
|  | ||||
| build-no-cache: dist | ||||
| 	docker build --no-cache -t "$(TRAEFIK_DEV_IMAGE)" -f build.Dockerfile . | ||||
| .PHONY: clean-webui | ||||
| #? clean-webui: Clean WebUI static generated assets | ||||
| clean-webui: | ||||
| 	rm -r webui/static | ||||
| 	mkdir -p webui/static | ||||
| 	printf 'For more information see `webui/readme.md`' > webui/static/DONT-EDIT-FILES-IN-THIS-DIRECTORY.md | ||||
|  | ||||
| shell: build ## start a shell inside the build env | ||||
| 	$(DOCKER_RUN_TRAEFIK) /bin/bash | ||||
| webui/static/index.html: | ||||
| 	$(MAKE) build-webui-image | ||||
| 	docker run --rm -v "$(PWD)/webui/static":'/src/webui/static' traefik-webui npm run build:nc | ||||
| 	docker run --rm -v "$(PWD)/webui/static":'/src/webui/static' traefik-webui chown -R $(shell id -u):$(shell id -g) ./static | ||||
|  | ||||
| image-dirty: binary ## build a docker traefik image | ||||
| 	docker build -t $(TRAEFIK_IMAGE) . | ||||
| .PHONY: generate-webui | ||||
| #? generate-webui: Generate WebUI | ||||
| generate-webui: webui/static/index.html | ||||
|  | ||||
| image: clear-static binary ## clean up static directory and build a docker traefik image | ||||
| 	docker build -t $(TRAEFIK_IMAGE) . | ||||
|  | ||||
| docs: docs-image | ||||
| 	docker run  $(DOCKER_RUN_DOC_OPTS) $(TRAEFIK_DOC_IMAGE) mkdocs serve | ||||
|  | ||||
| docs-image: | ||||
| 	docker build -t $(TRAEFIK_DOC_IMAGE) -f docs.Dockerfile . | ||||
|  | ||||
| clear-static: | ||||
| 	rm -rf static | ||||
|  | ||||
| dist: | ||||
| 	mkdir dist | ||||
|  | ||||
| run-dev: | ||||
| .PHONY: generate | ||||
| #? generate: Generate code (Dynamic and Static configuration documentation reference files) | ||||
| generate: | ||||
| 	go generate | ||||
| 	go build ./cmd/traefik | ||||
| 	./traefik | ||||
|  | ||||
| generate-webui: build-webui | ||||
| 	if [ ! -d "static" ]; then \ | ||||
| 		mkdir -p static; \ | ||||
| 		docker run --rm -v "$$PWD/static":'/src/static' traefik-webui npm run build; \ | ||||
| 		echo 'For more informations show `webui/readme.md`' > $$PWD/static/DONT-EDIT-FILES-IN-THIS-DIRECTORY.md; \ | ||||
| 	fi | ||||
| .PHONY: binary | ||||
| #? binary: Build the binary | ||||
| binary: generate-webui dist | ||||
| 	@echo SHA: $(VERSION) $(CODENAME) $(DATE) | ||||
| 	CGO_ENABLED=0 GOGC=off GOOS=${GOOS} GOARCH=${GOARCH} go build ${FLAGS[*]} -ldflags "-s -w \ | ||||
|     -X github.com/traefik/traefik/v3/pkg/version.Version=$(VERSION) \ | ||||
|     -X github.com/traefik/traefik/v3/pkg/version.Codename=$(CODENAME) \ | ||||
|     -X github.com/traefik/traefik/v3/pkg/version.BuildDate=$(DATE)" \ | ||||
|     -installsuffix nocgo -o "./dist/${GOOS}/${GOARCH}/$(BIN_NAME)" ./cmd/traefik | ||||
|  | ||||
| binary-linux-arm64: export GOOS := linux | ||||
| binary-linux-arm64: export GOARCH := arm64 | ||||
| binary-linux-arm64: | ||||
| 	@$(MAKE) binary | ||||
|  | ||||
| binary-linux-amd64: export GOOS := linux | ||||
| binary-linux-amd64: export GOARCH := amd64 | ||||
| binary-linux-amd64: | ||||
| 	@$(MAKE) binary | ||||
|  | ||||
| binary-windows-amd64: export GOOS := windows | ||||
| binary-windows-amd64: export GOARCH := amd64 | ||||
| binary-windows-amd64: export BIN_NAME := traefik.exe | ||||
| binary-windows-amd64: | ||||
| 	@$(MAKE) binary | ||||
|  | ||||
| .PHONY: crossbinary-default | ||||
| #? crossbinary-default: Build the binary for the standard platforms (linux, darwin, windows) | ||||
| crossbinary-default: generate generate-webui | ||||
| 	$(CURDIR)/script/crossbinary-default.sh | ||||
|  | ||||
| .PHONY: test | ||||
| #? test: Run the unit and integration tests | ||||
| test: test-ui-unit test-unit test-integration | ||||
|  | ||||
| .PHONY: test-unit | ||||
| #? test-unit: Run the unit tests | ||||
| test-unit: | ||||
| 	GOOS=$(GOOS) GOARCH=$(GOARCH) go test -cover "-coverprofile=cover.out" -v $(TESTFLAGS) ./pkg/... ./cmd/... | ||||
|  | ||||
| .PHONY: test-integration | ||||
| #? test-integration: Run the integration tests | ||||
| test-integration: binary | ||||
| 	GOOS=$(GOOS) GOARCH=$(GOARCH) go test ./integration -test.timeout=20m -failfast -v $(TESTFLAGS) | ||||
|  | ||||
| .PHONY: test-gateway-api-conformance | ||||
| #? test-gateway-api-conformance: Run the conformance tests | ||||
| test-gateway-api-conformance: build-image-dirty | ||||
| 	GOOS=$(GOOS) GOARCH=$(GOARCH) go test ./integration -v -test.run K8sConformanceSuite -k8sConformance $(TESTFLAGS) | ||||
|  | ||||
| .PHONY: test-ui-unit | ||||
| #? test-ui-unit: Run the unit tests for the webui | ||||
| test-ui-unit: | ||||
| 	$(MAKE) build-webui-image | ||||
| 	docker run --rm -v "$(PWD)/webui/static":'/src/webui/static' traefik-webui yarn --cwd webui install | ||||
| 	docker run --rm -v "$(PWD)/webui/static":'/src/webui/static' traefik-webui yarn --cwd webui test:unit:ci | ||||
|  | ||||
| .PHONY: pull-images | ||||
| #? pull-images: Pull all Docker images to avoid timeout during integration tests | ||||
| pull-images: | ||||
| 	grep --no-filename -E '^\s+image:' ./integration/resources/compose/*.yml \ | ||||
| 		| awk '{print $$2}' \ | ||||
| 		| sort \ | ||||
| 		| uniq \ | ||||
| 		| xargs -P 6 -n 1 docker pull | ||||
|  | ||||
| .PHONY: lint | ||||
| #? lint: Run golangci-lint | ||||
| lint: | ||||
| 	script/validate-golint | ||||
| 	golangci-lint run | ||||
|  | ||||
| .PHONY: validate-files | ||||
| #? validate-files: Validate code and docs | ||||
| validate-files: lint | ||||
| 	$(foreach exec,$(LINT_EXECUTABLES),\ | ||||
|             $(if $(shell which $(exec)),,$(error "No $(exec) in PATH"))) | ||||
| 	$(CURDIR)/script/validate-misspell.sh | ||||
| 	$(CURDIR)/script/validate-shell-script.sh | ||||
|  | ||||
| .PHONY: validate | ||||
| #? validate: Validate code, docs, and vendor | ||||
| validate: lint | ||||
| 	$(foreach exec,$(EXECUTABLES),\ | ||||
|             $(if $(shell which $(exec)),,$(error "No $(exec) in PATH"))) | ||||
| 	$(CURDIR)/script/validate-vendor.sh | ||||
| 	$(CURDIR)/script/validate-misspell.sh | ||||
| 	$(CURDIR)/script/validate-shell-script.sh | ||||
|  | ||||
| # Target for building images for multiple architectures. | ||||
| .PHONY: multi-arch-image-% | ||||
| multi-arch-image-%: binary-linux-amd64 binary-linux-arm64 | ||||
| 	docker buildx build $(DOCKER_BUILDX_ARGS) -t traefik/traefik:$* --platform=$(DOCKER_BUILD_PLATFORMS) -f Dockerfile . | ||||
|  | ||||
|  | ||||
| .PHONY: build-image | ||||
| #? build-image: Clean up static directory and build a Docker Traefik image | ||||
| build-image: export DOCKER_BUILDX_ARGS := --load | ||||
| build-image: export DOCKER_BUILD_PLATFORMS := linux/$(GOARCH) | ||||
| build-image: clean-webui | ||||
| 	@$(MAKE) multi-arch-image-latest | ||||
|  | ||||
| .PHONY: build-image-dirty | ||||
| #? build-image-dirty: Build a Docker Traefik image without re-building the webui when it's already built | ||||
| build-image-dirty: export DOCKER_BUILDX_ARGS := --load | ||||
| build-image-dirty: export DOCKER_BUILD_PLATFORMS := linux/$(GOARCH) | ||||
| build-image-dirty: | ||||
| 	@$(MAKE) multi-arch-image-latest | ||||
|  | ||||
| .PHONY: docs | ||||
| #? docs: Build documentation site | ||||
| docs: | ||||
| 	make -C ./docs docs | ||||
|  | ||||
| .PHONY: docs-serve | ||||
| #? docs-serve: Serve the documentation site locally | ||||
| docs-serve: | ||||
| 	make -C ./docs docs-serve | ||||
|  | ||||
| .PHONY: docs-pull-images | ||||
| #? docs-pull-images: Pull image for doc building | ||||
| docs-pull-images: | ||||
| 	make -C ./docs docs-pull-images | ||||
|  | ||||
| .PHONY: generate-crd | ||||
| #? generate-crd: Generate CRD clientset and CRD manifests | ||||
| generate-crd: | ||||
| 	@$(CURDIR)/script/code-gen-docker.sh | ||||
|  | ||||
| .PHONY: generate-genconf | ||||
| #? generate-genconf: Generate code from dynamic configuration github.com/traefik/genconf | ||||
| generate-genconf: | ||||
| 	go run ./cmd/internal/gen/ | ||||
|  | ||||
| .PHONY: release-packages | ||||
| #? release-packages: Create packages for the release | ||||
| release-packages: generate-webui | ||||
| 	$(CURDIR)/script/release-packages.sh | ||||
|  | ||||
| .PHONY: fmt | ||||
| #? fmt: Format the Code | ||||
| fmt: | ||||
| 	gofmt -s -l -w $(SRCS) | ||||
|  | ||||
| pull-images: | ||||
| 	grep --no-filename -E '^\s+image:' ./integration/resources/compose/*.yml | awk '{print $$2}' | sort | uniq  | xargs -P 6 -n 1 docker pull | ||||
|  | ||||
| dep-ensure: | ||||
| 	dep ensure -v | ||||
| 	./script/prune-dep.sh | ||||
|  | ||||
| dep-prune: | ||||
| 	./script/prune-dep.sh | ||||
|  | ||||
| help: ## this help | ||||
| 	@awk 'BEGIN {FS = ":.*?## "} /^[a-zA-Z_-]+:.*?## / {sub("\\\\n",sprintf("\n%22c"," "), $$2);printf "\033[36m%-20s\033[0m %s\n", $$1, $$2}' $(MAKEFILE_LIST) | ||||
| .PHONY: help | ||||
| #? help: Get more info on make commands | ||||
| help: Makefile | ||||
| 	@echo " Choose a command run in traefik:" | ||||
| 	@sed -n 's/^#?//p' $< | column -t -s ':' |  sort | sed -e 's/^/ /' | ||||
|   | ||||
							
								
								
									
										134
									
								
								README.md
									
									
									
									
									
								
							
							
						
						
									
										134
									
								
								README.md
									
									
									
									
									
								
							| @@ -1,20 +1,22 @@ | ||||
|  | ||||
| <p align="center"> | ||||
| <img src="docs/img/traefik.logo.png" alt="Træfik" title="Træfik" /> | ||||
|     <picture> | ||||
|       <source media="(prefers-color-scheme: dark)" srcset="docs/content/assets/img/traefik.logo-dark.png"> | ||||
|       <source media="(prefers-color-scheme: light)" srcset="docs/content/assets/img/traefik.logo.png"> | ||||
|       <img alt="Traefik" title="Traefik" src="docs/content/assets/img/traefik.logo.png"> | ||||
|     </picture> | ||||
| </p> | ||||
|  | ||||
| [](https://semaphoreci.com/containous/traefik) | ||||
| [](https://docs.traefik.io) | ||||
| [](http://goreportcard.com/report/containous/traefik) | ||||
| [](https://microbadger.com/images/traefik) | ||||
| [](https://github.com/containous/traefik/blob/master/LICENSE.md) | ||||
| [](https://traefik.herokuapp.com) | ||||
| [](https://twitter.com/intent/follow?screen_name=traefikproxy) | ||||
| [](https://traefik-oss.semaphoreci.com/projects/traefik) | ||||
| [](https://doc.traefik.io/traefik) | ||||
| [](https://goreportcard.com/report/traefik/traefik) | ||||
| [](https://github.com/traefik/traefik/blob/master/LICENSE.md) | ||||
| [](https://community.traefik.io/) | ||||
| [](https://twitter.com/intent/follow?screen_name=traefik) | ||||
|  | ||||
|  | ||||
| Træfik is a modern HTTP reverse proxy and load balancer that makes deploying microservices easy. | ||||
| Træfik integrates with your existing infrastructure components ([Docker](https://www.docker.com/), [Swarm mode](https://docs.docker.com/engine/swarm/), [Kubernetes](https://kubernetes.io), [Marathon](https://mesosphere.github.io/marathon/), [Consul](https://www.consul.io/), [Etcd](https://coreos.com/etcd/), [Rancher](https://rancher.com), [Amazon ECS](https://aws.amazon.com/ecs), ...) and configures itself automatically and dynamically. | ||||
| Telling Træfik where your orchestrator is could be the _only_ configuration step you need to do. | ||||
| Traefik (pronounced _traffic_) is a modern HTTP reverse proxy and load balancer that makes deploying microservices easy. | ||||
| Traefik integrates with your existing infrastructure components ([Docker](https://www.docker.com/), [Swarm mode](https://docs.docker.com/engine/swarm/), [Kubernetes](https://kubernetes.io), [Consul](https://www.consul.io/), [Etcd](https://coreos.com/etcd/), [Rancher v2](https://rancher.com), [Amazon ECS](https://aws.amazon.com/ecs), ...) and configures itself automatically and dynamically. | ||||
| Pointing Traefik at your orchestrator should be the _only_ configuration step you need. | ||||
|  | ||||
| --- | ||||
|  | ||||
| @@ -23,18 +25,18 @@ Telling Træfik where your orchestrator is could be the _only_ configuration ste | ||||
| **[Supported backends](#supported-backends)** . | ||||
| **[Quickstart](#quickstart)** . | ||||
| **[Web UI](#web-ui)** . | ||||
| **[Test it](#test-it)** . | ||||
| **[Documentation](#documentation)** . | ||||
|  | ||||
| . **[Support](#support)** . | ||||
| **[Release cycle](#release-cycle)** . | ||||
| **[Contributing](#contributing)** . | ||||
| **[Maintainers](#maintainers)** . | ||||
| **[Plumbing](#plumbing)** . | ||||
| **[Credits](#credits)** . | ||||
|  | ||||
| --- | ||||
|  | ||||
| :warning: Please be aware that the old configurations for Traefik v1.x are NOT compatible with the v2.x config as of now. If you're running v2, please ensure you are using a [v2 configuration](https://doc.traefik.io/traefik/). | ||||
|  | ||||
| ## Overview | ||||
|  | ||||
| Imagine that you have deployed a bunch of microservices with the help of an orchestrator (like Swarm or Kubernetes) or a service registry (like etcd or consul). | ||||
| @@ -43,14 +45,14 @@ Now you want users to access these microservices, and you need a reverse proxy. | ||||
| Traditional reverse-proxies require that you configure _each_ route that will connect paths and subdomains to _each_ microservice.  | ||||
| In an environment where you add, remove, kill, upgrade, or scale your services _many_ times a day, the task of keeping the routes up to date becomes tedious.  | ||||
|  | ||||
| **This is when Træfik can help you!** | ||||
| **This is when Traefik can help you!** | ||||
|  | ||||
| Træfik listens to your service registry/orchestrator API and instantly generates the routes so your microservices are connected to the outside world -- without further intervention from your part.  | ||||
| Traefik listens to your service registry/orchestrator API and instantly generates the routes so your microservices are connected to the outside world -- without further intervention from your part.  | ||||
|  | ||||
| **Run Træfik and let it do the work for you!**  | ||||
| _(But if you'd rather configure some of your routes manually, Træfik supports that too!)_ | ||||
| **Run Traefik and let it do the work for you!**  | ||||
| _(But if you'd rather configure some of your routes manually, Traefik supports that too!)_ | ||||
|  | ||||
|  | ||||
|  | ||||
|  | ||||
| ## Features | ||||
|  | ||||
| @@ -58,68 +60,54 @@ _(But if you'd rather configure some of your routes manually, Træfik supports t | ||||
| - Supports multiple load balancing algorithms | ||||
| - Provides HTTPS to your microservices by leveraging [Let's Encrypt](https://letsencrypt.org)  (wildcard certificates support) | ||||
| - Circuit breakers, retry | ||||
| - High Availability with cluster mode (beta) | ||||
| - See the magic through its clean web UI | ||||
| - Websocket, HTTP/2, GRPC ready | ||||
| - Provides metrics (Rest, Prometheus, Datadog, Statsd, InfluxDB) | ||||
| - Websocket, HTTP/2, gRPC ready | ||||
| - Provides metrics (Rest, Prometheus, Datadog, Statsd, InfluxDB 2.X) | ||||
| - Keeps access logs (JSON, CLF) | ||||
| - [Fast](https://docs.traefik.io/benchmarks) ... which is nice | ||||
| - Fast | ||||
| - Exposes a Rest API | ||||
| - Packaged as a single binary file (made with :heart: with go) and available as a [tiny](https://microbadger.com/images/traefik) [official](https://hub.docker.com/r/_/traefik/) docker image | ||||
|  | ||||
| - Packaged as a single binary file (made with :heart: with go) and available as an [official](https://hub.docker.com/r/_/traefik/) docker image | ||||
|  | ||||
| ## Supported Backends | ||||
|  | ||||
| - [Docker](docs/configuration/backends/docker/) / [Swarm mode](docs/configuration/backends/docker/#docker-swarm-mode) | ||||
| - [Kubernetes](docs/configuration/backends/kubernetes/) | ||||
| - [Mesos](docs/configuration/backends/mesos/) / [Marathon](docs/configuration/backends/marathon/) | ||||
| - [Rancher](docs/configuration/backends/rancher/) (API, Metadata) | ||||
| - [Service Fabric](docs/configuration/backends/servicefabric/) | ||||
| - [Consul Catalog](docs/configuration/backends/consulcatalog/) | ||||
| - [Consul](docs/configuration/backends/consul/) / [Etcd](docs/configuration/backends/etcd/) / [Zookeeper](docs/configuration/backends/zookeeper/) / [BoltDB](docs/configuration/backends/boltdb/) | ||||
| - [Eureka](docs/configuration/backends/eureka/) | ||||
| - [Amazon ECS](docs/configuration/backends/ecs/) | ||||
| - [Amazon DynamoDB](docs/configuration/backends/dynamodb/) | ||||
| - [File](docs/configuration/backends/file/) | ||||
| - [Rest](docs/configuration/backends/rest/) | ||||
| - [Docker](https://doc.traefik.io/traefik/providers/docker/) / [Swarm mode](https://doc.traefik.io/traefik/providers/docker/) | ||||
| - [Kubernetes](https://doc.traefik.io/traefik/providers/kubernetes-crd/) | ||||
| - [ECS](https://doc.traefik.io/traefik/providers/ecs/) | ||||
| - [File](https://doc.traefik.io/traefik/providers/file/) | ||||
|  | ||||
| ## Quickstart | ||||
|  | ||||
| To get your hands on Træfik, you can use the [5-Minute Quickstart](http://docs.traefik.io/#the-trfik-quickstart-using-docker) in our documentation (you will need Docker). | ||||
|  | ||||
| Alternatively, if you don't want to install anything on your computer, you can try Træfik online in this great [Katacoda tutorial](https://www.katacoda.com/courses/traefik/deploy-load-balancer) that shows how to load balance requests between multiple Docker containers.  | ||||
|  | ||||
| If you are looking for a more comprehensive and real use-case example, you can also check [Play-With-Docker](http://training.play-with-docker.com/traefik-load-balancing/) to see how to load balance between multiple nodes. | ||||
| To get your hands on Traefik, you can use the [5-Minute Quickstart](https://doc.traefik.io/traefik/getting-started/quick-start/) in our documentation (you will need Docker). | ||||
|  | ||||
| ## Web UI | ||||
|  | ||||
| You can access the simple HTML frontend of Træfik. | ||||
| You can access the simple HTML frontend of Traefik. | ||||
|  | ||||
|  | ||||
|  | ||||
|  | ||||
|  | ||||
| ## Documentation | ||||
|  | ||||
| You can find the complete documentation at [https://docs.traefik.io](https://docs.traefik.io). | ||||
| A collection of contributions around Træfik can be found at [https://awesome.traefik.io](https://awesome.traefik.io). | ||||
| You can find the complete documentation of Traefik v2 at [https://doc.traefik.io/traefik/](https://doc.traefik.io/traefik/). | ||||
|  | ||||
| A collection of contributions around Traefik can be found at [https://awesome.traefik.io](https://awesome.traefik.io). | ||||
|  | ||||
| ## Support | ||||
|  | ||||
| To get community support, you can: | ||||
| - join the Træfik community Slack channel: [](https://traefik.herokuapp.com) | ||||
| - use [Stack Overflow](https://stackoverflow.com/questions/tagged/traefik) (using the `traefik` tag) | ||||
|  | ||||
| If you need commercial support, please contact [Containo.us](https://containo.us) by mail: <mailto:support@containo.us>. | ||||
| - join the Traefik community forum: [](https://community.traefik.io/) | ||||
|  | ||||
| If you need commercial support, please contact [Traefik.io](https://traefik.io) by mail: <mailto:support@traefik.io>. | ||||
|  | ||||
| ## Download | ||||
|  | ||||
| - Grab the latest binary from the [releases](https://github.com/containous/traefik/releases) page and run it with the [sample configuration file](https://raw.githubusercontent.com/containous/traefik/master/traefik.sample.toml): | ||||
| - Grab the latest binary from the [releases](https://github.com/traefik/traefik/releases) page and run it with the [sample configuration file](https://raw.githubusercontent.com/traefik/traefik/master/traefik.sample.toml): | ||||
|  | ||||
| ```shell | ||||
| ./traefik --configFile=traefik.toml | ||||
| ``` | ||||
|  | ||||
| - Or use the official tiny Docker image and run it with the [sample configuration file](https://raw.githubusercontent.com/containous/traefik/master/traefik.sample.toml): | ||||
| - Or use the official tiny Docker image and run it with the [sample configuration file](https://raw.githubusercontent.com/traefik/traefik/master/traefik.sample.toml): | ||||
|  | ||||
| ```shell | ||||
| docker run -d -p 8080:8080 -p 80:80 -v $PWD/traefik.toml:/etc/traefik/traefik.toml traefik | ||||
| @@ -128,24 +116,18 @@ docker run -d -p 8080:8080 -p 80:80 -v $PWD/traefik.toml:/etc/traefik/traefik.to | ||||
| - Or get the sources: | ||||
|  | ||||
| ```shell | ||||
| git clone https://github.com/containous/traefik | ||||
| git clone https://github.com/traefik/traefik | ||||
| ``` | ||||
|  | ||||
| ## Introductory Videos | ||||
|  | ||||
| Here is a talk given by [Emile Vauge](https://github.com/emilevauge) at [GopherCon 2017](https://gophercon.com/). | ||||
| You will learn Træfik basics in less than 10 minutes. | ||||
|  | ||||
| [](https://www.youtube.com/watch?v=RgudiksfL-k) | ||||
|  | ||||
| Here is a talk given by [Ed Robinson](https://github.com/errm) at [ContainerCamp UK](https://container.camp) conference. | ||||
| You will learn fundamental Træfik features and see some demos with Kubernetes. | ||||
|  | ||||
| [](https://www.youtube.com/watch?v=aFtpIShV60I) | ||||
| You can find high level and deep dive videos on [videos.traefik.io](https://videos.traefik.io). | ||||
|  | ||||
| ## Maintainers | ||||
|  | ||||
| [Information about process and maintainers](MAINTAINER.md) | ||||
| We are strongly promoting a philosophy of openness and sharing, and firmly standing against the elitist closed approach. Being part of the core team should be accessible to anyone who is motivated and want to be part of that journey! | ||||
| This [document](docs/content/contributing/maintainers-guidelines.md) describes how to be part of the [maintainers' team](docs/content/contributing/maintainers.md) as well as various responsibilities and guidelines for Traefik maintainers. | ||||
| You can also find more information on our process to review pull requests and manage issues [in this document](https://github.com/traefik/contributors-guide/blob/master/issue_triage.md). | ||||
|  | ||||
| ## Contributing | ||||
|  | ||||
| @@ -156,26 +138,24 @@ By participating in this project, you agree to abide by its terms. | ||||
|  | ||||
| ## Release Cycle | ||||
|  | ||||
| - We release a new version (e.g. 1.1.0, 1.2.0, 1.3.0) every other month. | ||||
| - Release Candidates are available before the release (e.g. 1.1.0-rc1, 1.1.0-rc2, 1.1.0-rc3, 1.1.0-rc4, before 1.1.0) | ||||
| - Bug-fixes (e.g. 1.1.1, 1.1.2, 1.2.1, 1.2.3) are released as needed (no additional features are delivered in those versions, bug-fixes only) | ||||
| - We usually release 3/4 new versions (e.g. 1.1.0, 1.2.0, 1.3.0) per year. | ||||
| - Release Candidates are available before the release (e.g. 1.1.0-rc1, 1.1.0-rc2, 1.1.0-rc3, 1.1.0-rc4, before 1.1.0). | ||||
| - Bug-fixes (e.g. 1.1.1, 1.1.2, 1.2.1, 1.2.3) are released as needed (no additional features are delivered in those versions, bug-fixes only). | ||||
|  | ||||
| Each version is supported until the next one is released (e.g. 1.1.x will be supported until 1.2.0 is out) | ||||
| Each version is supported until the next one is released (e.g. 1.1.x will be supported until 1.2.0 is out). | ||||
|  | ||||
| We use [Semantic Versioning](http://semver.org/) | ||||
| We use [Semantic Versioning](https://semver.org/). | ||||
|  | ||||
| ## Plumbing | ||||
| ## Mailing Lists | ||||
|  | ||||
| - [Oxy](https://github.com/vulcand/oxy): an awesome proxy library made by Mailgun folks | ||||
| - [Gorilla mux](https://github.com/gorilla/mux): famous request router | ||||
| - [Negroni](https://github.com/urfave/negroni): web middlewares made simple | ||||
| - [Lego](https://github.com/xenolf/lego): the best [Let's Encrypt](https://letsencrypt.org) library in go | ||||
| - General announcements, new releases: mail at news+subscribe@traefik.io or on [the online viewer](https://groups.google.com/a/traefik.io/forum/#!forum/news). | ||||
| - Security announcements: mail at security+subscribe@traefik.io or on [the online viewer](https://groups.google.com/a/traefik.io/forum/#!forum/security). | ||||
|  | ||||
| ## Credits | ||||
|  | ||||
| Kudos to [Peka](http://peka.byethost11.com/photoblog/) for his awesome work on the logo . | ||||
| Kudos to [Peka](http://peka.byethost11.com/photoblog/) for his awesome work on the gopher's logo!. | ||||
|  | ||||
| Traefik's logo is licensed under the Creative Commons 3.0 Attributions license. | ||||
| The gopher's logo of Traefik is licensed under the Creative Commons 3.0 Attributions license. | ||||
|  | ||||
| Traefik's logo was inspired by the gopher stickers made by Takuya Ueda (https://twitter.com/tenntenn). | ||||
| The original Go gopher was designed by Renee French (http://reneefrench.blogspot.com/). | ||||
| The gopher's logo of Traefik was inspired by the gopher stickers made by [Takuya Ueda](https://twitter.com/tenntenn). | ||||
| The original Go gopher was designed by [Renee French](https://reneefrench.blogspot.com/). | ||||
|   | ||||
							
								
								
									
										30
									
								
								SECURITY.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										30
									
								
								SECURITY.md
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,30 @@ | ||||
| # Security Policy | ||||
|  | ||||
| You can join our security mailing list to be aware of the latest announcements from our security team. | ||||
| You can subscribe sending a mail to security+subscribe@traefik.io or on [the online viewer](https://groups.google.com/a/traefik.io/forum/#!forum/security). | ||||
|  | ||||
| Reported vulnerabilities can be found on [cve.mitre.org](https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=traefik). | ||||
|  | ||||
| ## Supported Versions | ||||
|  | ||||
| - We usually release 3/4 new versions (e.g. 1.1.0, 1.2.0, 1.3.0) per year. | ||||
| - Release Candidates are available before the release (e.g. 1.1.0-rc1, 1.1.0-rc2, 1.1.0-rc3, 1.1.0-rc4, before 1.1.0). | ||||
| - Bug-fixes (e.g. 1.1.1, 1.1.2, 1.2.1, 1.2.3) are released as needed (no additional features are delivered in those versions, bug-fixes only). | ||||
|  | ||||
| Each version is supported until the next one is released (e.g. 1.1.x will be supported until 1.2.0 is out). | ||||
|  | ||||
| We use [Semantic Versioning](https://semver.org/). | ||||
|  | ||||
| | Version   | Supported          | | ||||
| |-----------|--------------------| | ||||
| | `2.2.x`   | :white_check_mark: | | ||||
| | `< 2.2.x` | :x:                | | ||||
| | `1.7.x`   | :white_check_mark: | | ||||
| | `< 1.7.x` | :x:                | | ||||
|  | ||||
| ## Reporting a Vulnerability | ||||
|  | ||||
| We want to keep Traefik safe for everyone. | ||||
| If you've discovered a security vulnerability in Traefik, | ||||
| we appreciate your help in disclosing it to us in a responsible manner, | ||||
| by creating a [security advisory](https://github.com/traefik/traefik/security/advisories). | ||||
							
								
								
									
										287
									
								
								acme/account.go
									
									
									
									
									
								
							
							
						
						
									
										287
									
								
								acme/account.go
									
									
									
									
									
								
							| @@ -1,287 +0,0 @@ | ||||
| package acme | ||||
|  | ||||
| import ( | ||||
| 	"crypto" | ||||
| 	"crypto/rand" | ||||
| 	"crypto/rsa" | ||||
| 	"crypto/tls" | ||||
| 	"crypto/x509" | ||||
| 	"fmt" | ||||
| 	"reflect" | ||||
| 	"sort" | ||||
| 	"strings" | ||||
| 	"sync" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/types" | ||||
| 	acme "github.com/xenolf/lego/acmev2" | ||||
| ) | ||||
|  | ||||
| // Account is used to store lets encrypt registration info | ||||
| type Account struct { | ||||
| 	Email              string | ||||
| 	Registration       *acme.RegistrationResource | ||||
| 	PrivateKey         []byte | ||||
| 	DomainsCertificate DomainsCertificates | ||||
| 	ChallengeCerts     map[string]*ChallengeCert | ||||
| 	HTTPChallenge      map[string]map[string][]byte | ||||
| } | ||||
|  | ||||
| // ChallengeCert stores a challenge certificate | ||||
| type ChallengeCert struct { | ||||
| 	Certificate []byte | ||||
| 	PrivateKey  []byte | ||||
| 	certificate *tls.Certificate | ||||
| } | ||||
|  | ||||
| // Init account struct | ||||
| func (a *Account) Init() error { | ||||
| 	err := a.DomainsCertificate.Init() | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	for _, cert := range a.ChallengeCerts { | ||||
| 		if cert.certificate == nil { | ||||
| 			certificate, err := tls.X509KeyPair(cert.Certificate, cert.PrivateKey) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
| 			cert.certificate = &certificate | ||||
| 		} | ||||
|  | ||||
| 		if cert.certificate.Leaf == nil { | ||||
| 			leaf, err := x509.ParseCertificate(cert.certificate.Certificate[0]) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
| 			cert.certificate.Leaf = leaf | ||||
| 		} | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| // NewAccount creates an account | ||||
| func NewAccount(email string, certs []*DomainsCertificate) (*Account, error) { | ||||
| 	// Create a user. New accounts need an email and private key to start | ||||
| 	privateKey, err := rsa.GenerateKey(rand.Reader, 4096) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	domainsCerts := DomainsCertificates{Certs: certs} | ||||
| 	err = domainsCerts.Init() | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	return &Account{ | ||||
| 		Email:              email, | ||||
| 		PrivateKey:         x509.MarshalPKCS1PrivateKey(privateKey), | ||||
| 		DomainsCertificate: DomainsCertificates{Certs: domainsCerts.Certs}, | ||||
| 		ChallengeCerts:     map[string]*ChallengeCert{}}, nil | ||||
| } | ||||
|  | ||||
| // GetEmail returns email | ||||
| func (a *Account) GetEmail() string { | ||||
| 	return a.Email | ||||
| } | ||||
|  | ||||
| // GetRegistration returns lets encrypt registration resource | ||||
| func (a *Account) GetRegistration() *acme.RegistrationResource { | ||||
| 	return a.Registration | ||||
| } | ||||
|  | ||||
| // GetPrivateKey returns private key | ||||
| func (a *Account) GetPrivateKey() crypto.PrivateKey { | ||||
| 	if privateKey, err := x509.ParsePKCS1PrivateKey(a.PrivateKey); err == nil { | ||||
| 		return privateKey | ||||
| 	} | ||||
|  | ||||
| 	log.Errorf("Cannot unmarshall private key %+v", a.PrivateKey) | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| // Certificate is used to store certificate info | ||||
| type Certificate struct { | ||||
| 	Domain        string | ||||
| 	CertURL       string | ||||
| 	CertStableURL string | ||||
| 	PrivateKey    []byte | ||||
| 	Certificate   []byte | ||||
| } | ||||
|  | ||||
| // DomainsCertificates stores a certificate for multiple domains | ||||
| type DomainsCertificates struct { | ||||
| 	Certs []*DomainsCertificate | ||||
| 	lock  sync.RWMutex | ||||
| } | ||||
|  | ||||
| func (dc *DomainsCertificates) Len() int { | ||||
| 	return len(dc.Certs) | ||||
| } | ||||
|  | ||||
| func (dc *DomainsCertificates) Swap(i, j int) { | ||||
| 	dc.Certs[i], dc.Certs[j] = dc.Certs[j], dc.Certs[i] | ||||
| } | ||||
|  | ||||
| func (dc *DomainsCertificates) Less(i, j int) bool { | ||||
| 	if reflect.DeepEqual(dc.Certs[i].Domains, dc.Certs[j].Domains) { | ||||
| 		return dc.Certs[i].tlsCert.Leaf.NotAfter.After(dc.Certs[j].tlsCert.Leaf.NotAfter) | ||||
| 	} | ||||
|  | ||||
| 	if dc.Certs[i].Domains.Main == dc.Certs[j].Domains.Main { | ||||
| 		return strings.Join(dc.Certs[i].Domains.SANs, ",") < strings.Join(dc.Certs[j].Domains.SANs, ",") | ||||
| 	} | ||||
|  | ||||
| 	return dc.Certs[i].Domains.Main < dc.Certs[j].Domains.Main | ||||
| } | ||||
|  | ||||
| func (dc *DomainsCertificates) removeDuplicates() { | ||||
| 	sort.Sort(dc) | ||||
| 	for i := 0; i < len(dc.Certs); i++ { | ||||
| 		for i2 := i + 1; i2 < len(dc.Certs); i2++ { | ||||
| 			if reflect.DeepEqual(dc.Certs[i].Domains, dc.Certs[i2].Domains) { | ||||
| 				// delete | ||||
| 				log.Warnf("Remove duplicate cert: %+v, expiration :%s", dc.Certs[i2].Domains, dc.Certs[i2].tlsCert.Leaf.NotAfter.String()) | ||||
| 				dc.Certs = append(dc.Certs[:i2], dc.Certs[i2+1:]...) | ||||
| 				i2-- | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // Init DomainsCertificates | ||||
| func (dc *DomainsCertificates) Init() error { | ||||
| 	dc.lock.Lock() | ||||
| 	defer dc.lock.Unlock() | ||||
|  | ||||
| 	for _, domainsCertificate := range dc.Certs { | ||||
| 		tlsCert, err := tls.X509KeyPair(domainsCertificate.Certificate.Certificate, domainsCertificate.Certificate.PrivateKey) | ||||
| 		if err != nil { | ||||
| 			return err | ||||
| 		} | ||||
|  | ||||
| 		domainsCertificate.tlsCert = &tlsCert | ||||
|  | ||||
| 		if domainsCertificate.tlsCert.Leaf == nil { | ||||
| 			leaf, err := x509.ParseCertificate(domainsCertificate.tlsCert.Certificate[0]) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
|  | ||||
| 			domainsCertificate.tlsCert.Leaf = leaf | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	dc.removeDuplicates() | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func (dc *DomainsCertificates) renewCertificates(acmeCert *Certificate, domain types.Domain) error { | ||||
| 	dc.lock.Lock() | ||||
| 	defer dc.lock.Unlock() | ||||
|  | ||||
| 	for _, domainsCertificate := range dc.Certs { | ||||
| 		if reflect.DeepEqual(domain, domainsCertificate.Domains) { | ||||
| 			tlsCert, err := tls.X509KeyPair(acmeCert.Certificate, acmeCert.PrivateKey) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
|  | ||||
| 			domainsCertificate.Certificate = acmeCert | ||||
| 			domainsCertificate.tlsCert = &tlsCert | ||||
| 			return nil | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return fmt.Errorf("certificate to renew not found for domain %s", domain.Main) | ||||
| } | ||||
|  | ||||
| func (dc *DomainsCertificates) addCertificateForDomains(acmeCert *Certificate, domain types.Domain) (*DomainsCertificate, error) { | ||||
| 	dc.lock.Lock() | ||||
| 	defer dc.lock.Unlock() | ||||
|  | ||||
| 	tlsCert, err := tls.X509KeyPair(acmeCert.Certificate, acmeCert.PrivateKey) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	cert := DomainsCertificate{Domains: domain, Certificate: acmeCert, tlsCert: &tlsCert} | ||||
| 	dc.Certs = append(dc.Certs, &cert) | ||||
| 	return &cert, nil | ||||
| } | ||||
|  | ||||
| func (dc *DomainsCertificates) getCertificateForDomain(domainToFind string) (*DomainsCertificate, bool) { | ||||
| 	dc.lock.RLock() | ||||
| 	defer dc.lock.RUnlock() | ||||
|  | ||||
| 	for _, domainsCertificate := range dc.Certs { | ||||
| 		for _, domain := range domainsCertificate.Domains.ToStrArray() { | ||||
| 			if strings.HasPrefix(domain, "*.") && types.MatchDomain(domainToFind, domain) { | ||||
| 				return domainsCertificate, true | ||||
| 			} | ||||
| 			if domain == domainToFind { | ||||
| 				return domainsCertificate, true | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| 	return nil, false | ||||
| } | ||||
|  | ||||
| func (dc *DomainsCertificates) exists(domainToFind types.Domain) (*DomainsCertificate, bool) { | ||||
| 	dc.lock.RLock() | ||||
| 	defer dc.lock.RUnlock() | ||||
|  | ||||
| 	for _, domainsCertificate := range dc.Certs { | ||||
| 		if reflect.DeepEqual(domainToFind, domainsCertificate.Domains) { | ||||
| 			return domainsCertificate, true | ||||
| 		} | ||||
| 	} | ||||
| 	return nil, false | ||||
| } | ||||
|  | ||||
| func (dc *DomainsCertificates) toDomainsMap() map[string]*tls.Certificate { | ||||
| 	domainsCertificatesMap := make(map[string]*tls.Certificate) | ||||
|  | ||||
| 	for _, domainCertificate := range dc.Certs { | ||||
| 		certKey := domainCertificate.Domains.Main | ||||
|  | ||||
| 		if domainCertificate.Domains.SANs != nil { | ||||
| 			sort.Strings(domainCertificate.Domains.SANs) | ||||
|  | ||||
| 			for _, dnsName := range domainCertificate.Domains.SANs { | ||||
| 				if dnsName != domainCertificate.Domains.Main { | ||||
| 					certKey += fmt.Sprintf(",%s", dnsName) | ||||
| 				} | ||||
| 			} | ||||
| 		} | ||||
| 		domainsCertificatesMap[certKey] = domainCertificate.tlsCert | ||||
| 	} | ||||
| 	return domainsCertificatesMap | ||||
| } | ||||
|  | ||||
| // DomainsCertificate contains a certificate for multiple domains | ||||
| type DomainsCertificate struct { | ||||
| 	Domains     types.Domain | ||||
| 	Certificate *Certificate | ||||
| 	tlsCert     *tls.Certificate | ||||
| } | ||||
|  | ||||
| func (dc *DomainsCertificate) needRenew() bool { | ||||
| 	for _, c := range dc.tlsCert.Certificate { | ||||
| 		crt, err := x509.ParseCertificate(c) | ||||
| 		if err != nil { | ||||
| 			// If there's an error, we assume the cert is broken, and needs update | ||||
| 			return true | ||||
| 		} | ||||
|  | ||||
| 		// <= 30 days left, renew certificate | ||||
| 		if crt.NotAfter.Before(time.Now().Add(24 * 30 * time.Hour)) { | ||||
| 			return true | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return false | ||||
| } | ||||
							
								
								
									
										746
									
								
								acme/acme.go
									
									
									
									
									
								
							
							
						
						
									
										746
									
								
								acme/acme.go
									
									
									
									
									
								
							| @@ -1,746 +0,0 @@ | ||||
| package acme | ||||
|  | ||||
| import ( | ||||
| 	"context" | ||||
| 	"crypto/tls" | ||||
| 	"errors" | ||||
| 	"fmt" | ||||
| 	"io/ioutil" | ||||
| 	fmtlog "log" | ||||
| 	"net" | ||||
| 	"net/http" | ||||
| 	"os" | ||||
| 	"reflect" | ||||
| 	"strings" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/BurntSushi/ty/fun" | ||||
| 	"github.com/cenk/backoff" | ||||
| 	"github.com/containous/flaeg" | ||||
| 	"github.com/containous/mux" | ||||
| 	"github.com/containous/staert" | ||||
| 	"github.com/containous/traefik/cluster" | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	acmeprovider "github.com/containous/traefik/provider/acme" | ||||
| 	"github.com/containous/traefik/safe" | ||||
| 	"github.com/containous/traefik/tls/generate" | ||||
| 	"github.com/containous/traefik/types" | ||||
| 	"github.com/eapache/channels" | ||||
| 	"github.com/xenolf/lego/acmev2" | ||||
| 	"github.com/xenolf/lego/providers/dns" | ||||
| ) | ||||
|  | ||||
| var ( | ||||
| 	// OSCPMustStaple enables OSCP stapling as from https://github.com/xenolf/lego/issues/270 | ||||
| 	OSCPMustStaple = false | ||||
| ) | ||||
|  | ||||
| // ACME allows to connect to lets encrypt and retrieve certs | ||||
| // Deprecated Please use provider/acme/Provider | ||||
| type ACME struct { | ||||
| 	Email                 string                      `description:"Email address used for registration"` | ||||
| 	Domains               []types.Domain              `description:"SANs (alternative domains) to each main domain using format: --acme.domains='main.com,san1.com,san2.com' --acme.domains='main.net,san1.net,san2.net'"` | ||||
| 	Storage               string                      `description:"File or key used for certificates storage."` | ||||
| 	StorageFile           string                      // deprecated | ||||
| 	OnDemand              bool                        `description:"Enable on demand certificate generation. This will request a certificate from Let's Encrypt during the first TLS handshake for a hostname that does not yet have a certificate."` //deprecated | ||||
| 	OnHostRule            bool                        `description:"Enable certificate generation on frontends Host rules."` | ||||
| 	CAServer              string                      `description:"CA server to use."` | ||||
| 	EntryPoint            string                      `description:"Entrypoint to proxy acme challenge to."` | ||||
| 	DNSChallenge          *acmeprovider.DNSChallenge  `description:"Activate DNS-01 Challenge"` | ||||
| 	HTTPChallenge         *acmeprovider.HTTPChallenge `description:"Activate HTTP-01 Challenge"` | ||||
| 	DNSProvider           string                      `description:"Activate DNS-01 Challenge (Deprecated)"`                                                       // deprecated | ||||
| 	DelayDontCheckDNS     flaeg.Duration              `description:"Assume DNS propagates after a delay in seconds rather than finding and querying nameservers."` // deprecated | ||||
| 	ACMELogging           bool                        `description:"Enable debug logging of ACME actions."` | ||||
| 	client                *acme.Client | ||||
| 	defaultCertificate    *tls.Certificate | ||||
| 	store                 cluster.Store | ||||
| 	challengeHTTPProvider *challengeHTTPProvider | ||||
| 	checkOnDemandDomain   func(domain string) bool | ||||
| 	jobs                  *channels.InfiniteChannel | ||||
| 	TLSConfig             *tls.Config `description:"TLS config in case wildcard certs are used"` | ||||
| 	dynamicCerts          *safe.Safe | ||||
| } | ||||
|  | ||||
| func (a *ACME) init() error { | ||||
| 	// FIXME temporary fix, waiting for https://github.com/xenolf/lego/pull/478 | ||||
| 	acme.HTTPClient = http.Client{ | ||||
| 		Transport: &http.Transport{ | ||||
| 			Proxy: http.ProxyFromEnvironment, | ||||
| 			Dial: (&net.Dialer{ | ||||
| 				Timeout:   30 * time.Second, | ||||
| 				KeepAlive: 30 * time.Second, | ||||
| 			}).Dial, | ||||
| 			TLSHandshakeTimeout:   15 * time.Second, | ||||
| 			ResponseHeaderTimeout: 15 * time.Second, | ||||
| 			ExpectContinueTimeout: 1 * time.Second, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	if a.ACMELogging { | ||||
| 		acme.Logger = fmtlog.New(os.Stderr, "legolog: ", fmtlog.LstdFlags) | ||||
| 	} else { | ||||
| 		acme.Logger = fmtlog.New(ioutil.Discard, "", 0) | ||||
| 	} | ||||
| 	// no certificates in TLS config, so we add a default one | ||||
| 	cert, err := generate.DefaultCertificate() | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	a.defaultCertificate = cert | ||||
|  | ||||
| 	a.jobs = channels.NewInfiniteChannel() | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| // AddRoutes add routes on internal router | ||||
| func (a *ACME) AddRoutes(router *mux.Router) { | ||||
| 	router.Methods(http.MethodGet). | ||||
| 		Path(acme.HTTP01ChallengePath("{token}")). | ||||
| 		Handler(http.HandlerFunc(func(rw http.ResponseWriter, req *http.Request) { | ||||
| 			if a.challengeHTTPProvider == nil { | ||||
| 				rw.WriteHeader(http.StatusNotFound) | ||||
| 				return | ||||
| 			} | ||||
|  | ||||
| 			vars := mux.Vars(req) | ||||
| 			if token, ok := vars["token"]; ok { | ||||
| 				domain, _, err := net.SplitHostPort(req.Host) | ||||
| 				if err != nil { | ||||
| 					log.Debugf("Unable to split host and port: %v. Fallback to request host.", err) | ||||
| 					domain = req.Host | ||||
| 				} | ||||
| 				tokenValue := a.challengeHTTPProvider.getTokenValue(token, domain) | ||||
| 				if len(tokenValue) > 0 { | ||||
| 					rw.WriteHeader(http.StatusOK) | ||||
| 					rw.Write(tokenValue) | ||||
| 					return | ||||
| 				} | ||||
| 			} | ||||
| 			rw.WriteHeader(http.StatusNotFound) | ||||
| 		})) | ||||
| } | ||||
|  | ||||
| // CreateClusterConfig creates a tls.config using ACME configuration in cluster mode | ||||
| func (a *ACME) CreateClusterConfig(leadership *cluster.Leadership, tlsConfig *tls.Config, certs *safe.Safe, checkOnDemandDomain func(domain string) bool) error { | ||||
| 	err := a.init() | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	if len(a.Storage) == 0 { | ||||
| 		return errors.New("Empty Store, please provide a key for certs storage") | ||||
| 	} | ||||
| 	a.checkOnDemandDomain = checkOnDemandDomain | ||||
| 	a.dynamicCerts = certs | ||||
| 	tlsConfig.Certificates = append(tlsConfig.Certificates, *a.defaultCertificate) | ||||
| 	tlsConfig.GetCertificate = a.getCertificate | ||||
| 	a.TLSConfig = tlsConfig | ||||
| 	listener := func(object cluster.Object) error { | ||||
| 		account := object.(*Account) | ||||
| 		account.Init() | ||||
| 		if !leadership.IsLeader() { | ||||
| 			a.client, err = a.buildACMEClient(account) | ||||
| 			if err != nil { | ||||
| 				log.Errorf("Error building ACME client %+v: %s", object, err.Error()) | ||||
| 			} | ||||
| 		} | ||||
| 		return nil | ||||
| 	} | ||||
|  | ||||
| 	datastore, err := cluster.NewDataStore( | ||||
| 		leadership.Pool.Ctx(), | ||||
| 		staert.KvSource{ | ||||
| 			Store:  leadership.Store, | ||||
| 			Prefix: a.Storage, | ||||
| 		}, | ||||
| 		&Account{}, | ||||
| 		listener) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	a.store = datastore | ||||
|  | ||||
| 	ticker := time.NewTicker(24 * time.Hour) | ||||
| 	leadership.Pool.AddGoCtx(func(ctx context.Context) { | ||||
| 		log.Info("Starting ACME renew job...") | ||||
| 		defer log.Info("Stopped ACME renew job...") | ||||
| 		for { | ||||
| 			select { | ||||
| 			case <-ctx.Done(): | ||||
| 				return | ||||
| 			case <-ticker.C: | ||||
| 				a.renewCertificates() | ||||
| 			} | ||||
| 		} | ||||
| 	}) | ||||
|  | ||||
| 	leadership.AddListener(a.leadershipListener) | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func (a *ACME) leadershipListener(elected bool) error { | ||||
| 	if elected { | ||||
| 		_, err := a.store.Load() | ||||
| 		if err != nil { | ||||
| 			return err | ||||
| 		} | ||||
|  | ||||
| 		transaction, object, err := a.store.Begin() | ||||
| 		if err != nil { | ||||
| 			return err | ||||
| 		} | ||||
|  | ||||
| 		account := object.(*Account) | ||||
| 		account.Init() | ||||
|  | ||||
| 		var needRegister bool | ||||
| 		if account == nil || len(account.Email) == 0 { | ||||
| 			domainsCerts := DomainsCertificates{Certs: []*DomainsCertificate{}} | ||||
| 			if account != nil { | ||||
| 				domainsCerts = account.DomainsCertificate | ||||
| 			} | ||||
|  | ||||
| 			account, err = NewAccount(a.Email, domainsCerts.Certs) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
|  | ||||
| 			needRegister = true | ||||
| 		} | ||||
|  | ||||
| 		a.client, err = a.buildACMEClient(account) | ||||
| 		if err != nil { | ||||
| 			return err | ||||
| 		} | ||||
| 		if needRegister { | ||||
| 			// New users will need to register; be sure to save it | ||||
| 			log.Debug("Register...") | ||||
|  | ||||
| 			reg, err := a.client.Register(true) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
|  | ||||
| 			account.Registration = reg | ||||
| 		} | ||||
|  | ||||
| 		err = transaction.Commit(account) | ||||
| 		if err != nil { | ||||
| 			return err | ||||
| 		} | ||||
|  | ||||
| 		a.retrieveCertificates() | ||||
| 		a.renewCertificates() | ||||
| 		a.runJobs() | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func (a *ACME) getCertificate(clientHello *tls.ClientHelloInfo) (*tls.Certificate, error) { | ||||
| 	domain := types.CanonicalDomain(clientHello.ServerName) | ||||
| 	account := a.store.Get().(*Account) | ||||
|  | ||||
| 	if providedCertificate := a.getProvidedCertificate(domain); providedCertificate != nil { | ||||
| 		return providedCertificate, nil | ||||
| 	} | ||||
|  | ||||
| 	if domainCert, ok := account.DomainsCertificate.getCertificateForDomain(domain); ok { | ||||
| 		log.Debugf("ACME got domain cert %s", domain) | ||||
| 		return domainCert.tlsCert, nil | ||||
| 	} | ||||
| 	if a.OnDemand { | ||||
| 		if a.checkOnDemandDomain != nil && !a.checkOnDemandDomain(domain) { | ||||
| 			return nil, nil | ||||
| 		} | ||||
| 		return a.loadCertificateOnDemand(clientHello) | ||||
| 	} | ||||
| 	log.Debugf("No certificate found or generated for %s", domain) | ||||
| 	return nil, nil | ||||
| } | ||||
|  | ||||
| func (a *ACME) retrieveCertificates() { | ||||
| 	a.jobs.In() <- func() { | ||||
| 		log.Info("Retrieving ACME certificates...") | ||||
|  | ||||
| 		a.deleteUnnecessaryDomains() | ||||
|  | ||||
| 		for i := 0; i < len(a.Domains); i++ { | ||||
| 			domain := a.Domains[i] | ||||
|  | ||||
| 			// check if cert isn't already loaded | ||||
| 			account := a.store.Get().(*Account) | ||||
| 			if _, exists := account.DomainsCertificate.exists(domain); !exists { | ||||
| 				var domains []string | ||||
| 				domains = append(domains, domain.Main) | ||||
| 				domains = append(domains, domain.SANs...) | ||||
| 				domains, err := a.getValidDomains(domains, true) | ||||
| 				if err != nil { | ||||
| 					log.Errorf("Error validating ACME certificate for domain %q: %s", domains, err) | ||||
| 					continue | ||||
| 				} | ||||
|  | ||||
| 				certificateResource, err := a.getDomainsCertificates(domains) | ||||
| 				if err != nil { | ||||
| 					log.Errorf("Error getting ACME certificate for domain %q: %s", domains, err) | ||||
| 					continue | ||||
| 				} | ||||
|  | ||||
| 				transaction, object, err := a.store.Begin() | ||||
| 				if err != nil { | ||||
| 					log.Errorf("Error creating ACME store transaction from domain %q: %s", domain, err) | ||||
| 					continue | ||||
| 				} | ||||
|  | ||||
| 				account = object.(*Account) | ||||
| 				_, err = account.DomainsCertificate.addCertificateForDomains(certificateResource, domain) | ||||
| 				if err != nil { | ||||
| 					log.Errorf("Error adding ACME certificate for domain %q: %s", domains, err) | ||||
| 					continue | ||||
| 				} | ||||
|  | ||||
| 				if err = transaction.Commit(account); err != nil { | ||||
| 					log.Errorf("Error Saving ACME account %+v: %s", account, err) | ||||
| 					continue | ||||
| 				} | ||||
| 			} | ||||
| 		} | ||||
|  | ||||
| 		log.Info("Retrieved ACME certificates") | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func (a *ACME) renewCertificates() { | ||||
| 	a.jobs.In() <- func() { | ||||
| 		log.Info("Testing certificate renew...") | ||||
| 		account := a.store.Get().(*Account) | ||||
| 		for _, certificateResource := range account.DomainsCertificate.Certs { | ||||
| 			if certificateResource.needRenew() { | ||||
| 				log.Infof("Renewing certificate from LE : %+v", certificateResource.Domains) | ||||
| 				renewedACMECert, err := a.renewACMECertificate(certificateResource) | ||||
| 				if err != nil { | ||||
| 					log.Errorf("Error renewing certificate from LE: %v", err) | ||||
| 					continue | ||||
| 				} | ||||
| 				operation := func() error { | ||||
| 					return a.storeRenewedCertificate(certificateResource, renewedACMECert) | ||||
| 				} | ||||
| 				notify := func(err error, time time.Duration) { | ||||
| 					log.Warnf("Renewed certificate storage error: %v, retrying in %s", err, time) | ||||
| 				} | ||||
| 				ebo := backoff.NewExponentialBackOff() | ||||
| 				ebo.MaxElapsedTime = 60 * time.Second | ||||
| 				err = backoff.RetryNotify(safe.OperationWithRecover(operation), ebo, notify) | ||||
| 				if err != nil { | ||||
| 					log.Errorf("Datastore cannot sync: %v", err) | ||||
| 					continue | ||||
| 				} | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func (a *ACME) renewACMECertificate(certificateResource *DomainsCertificate) (*Certificate, error) { | ||||
| 	renewedCert, err := a.client.RenewCertificate(acme.CertificateResource{ | ||||
| 		Domain:        certificateResource.Certificate.Domain, | ||||
| 		CertURL:       certificateResource.Certificate.CertURL, | ||||
| 		CertStableURL: certificateResource.Certificate.CertStableURL, | ||||
| 		PrivateKey:    certificateResource.Certificate.PrivateKey, | ||||
| 		Certificate:   certificateResource.Certificate.Certificate, | ||||
| 	}, true, OSCPMustStaple) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	log.Infof("Renewed certificate from  LE: %+v", certificateResource.Domains) | ||||
| 	return &Certificate{ | ||||
| 		Domain:        renewedCert.Domain, | ||||
| 		CertURL:       renewedCert.CertURL, | ||||
| 		CertStableURL: renewedCert.CertStableURL, | ||||
| 		PrivateKey:    renewedCert.PrivateKey, | ||||
| 		Certificate:   renewedCert.Certificate, | ||||
| 	}, nil | ||||
| } | ||||
|  | ||||
| func (a *ACME) storeRenewedCertificate(certificateResource *DomainsCertificate, renewedACMECert *Certificate) error { | ||||
| 	transaction, object, err := a.store.Begin() | ||||
| 	if err != nil { | ||||
| 		return fmt.Errorf("error during transaction initialization for renewing certificate: %v", err) | ||||
| 	} | ||||
|  | ||||
| 	log.Infof("Renewing certificate in data store : %+v ", certificateResource.Domains) | ||||
| 	account := object.(*Account) | ||||
| 	err = account.DomainsCertificate.renewCertificates(renewedACMECert, certificateResource.Domains) | ||||
| 	if err != nil { | ||||
| 		return fmt.Errorf("error renewing certificate in datastore: %v ", err) | ||||
| 	} | ||||
|  | ||||
| 	log.Infof("Commit certificate renewed in data store : %+v", certificateResource.Domains) | ||||
| 	if err = transaction.Commit(account); err != nil { | ||||
| 		return fmt.Errorf("error saving ACME account %+v: %v", account, err) | ||||
| 	} | ||||
|  | ||||
| 	oldAccount := a.store.Get().(*Account) | ||||
| 	for _, oldCertificateResource := range oldAccount.DomainsCertificate.Certs { | ||||
| 		if oldCertificateResource.Domains.Main == certificateResource.Domains.Main && strings.Join(oldCertificateResource.Domains.SANs, ",") == strings.Join(certificateResource.Domains.SANs, ",") && certificateResource.Certificate != renewedACMECert { | ||||
| 			return fmt.Errorf("renewed certificate not stored: %+v", certificateResource.Domains) | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	log.Infof("Certificate successfully renewed in data store: %+v", certificateResource.Domains) | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func dnsOverrideDelay(delay flaeg.Duration) error { | ||||
| 	var err error | ||||
| 	if delay > 0 { | ||||
| 		log.Debugf("Delaying %d rather than validating DNS propagation", delay) | ||||
| 		acme.PreCheckDNS = func(_, _ string) (bool, error) { | ||||
| 			time.Sleep(time.Duration(delay)) | ||||
| 			return true, nil | ||||
| 		} | ||||
| 	} else if delay < 0 { | ||||
| 		err = fmt.Errorf("invalid negative DelayBeforeCheck: %d", delay) | ||||
| 	} | ||||
| 	return err | ||||
| } | ||||
|  | ||||
| func (a *ACME) buildACMEClient(account *Account) (*acme.Client, error) { | ||||
| 	log.Debug("Building ACME client...") | ||||
| 	caServer := "https://acme-v02.api.letsencrypt.org/directory" | ||||
| 	if len(a.CAServer) > 0 { | ||||
| 		caServer = a.CAServer | ||||
| 	} | ||||
| 	client, err := acme.NewClient(caServer, account, acme.RSA4096) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	if a.DNSChallenge != nil && len(a.DNSChallenge.Provider) > 0 { | ||||
| 		log.Debugf("Using DNS Challenge provider: %s", a.DNSChallenge.Provider) | ||||
|  | ||||
| 		err = dnsOverrideDelay(a.DNSChallenge.DelayBeforeCheck) | ||||
| 		if err != nil { | ||||
| 			return nil, err | ||||
| 		} | ||||
|  | ||||
| 		var provider acme.ChallengeProvider | ||||
| 		provider, err = dns.NewDNSChallengeProviderByName(a.DNSChallenge.Provider) | ||||
| 		if err != nil { | ||||
| 			return nil, err | ||||
| 		} | ||||
|  | ||||
| 		client.ExcludeChallenges([]acme.Challenge{acme.HTTP01}) | ||||
| 		err = client.SetChallengeProvider(acme.DNS01, provider) | ||||
| 	} else if a.HTTPChallenge != nil && len(a.HTTPChallenge.EntryPoint) > 0 { | ||||
| 		log.Debug("Using HTTP Challenge provider.") | ||||
| 		client.ExcludeChallenges([]acme.Challenge{acme.DNS01}) | ||||
| 		a.challengeHTTPProvider = &challengeHTTPProvider{store: a.store} | ||||
| 		err = client.SetChallengeProvider(acme.HTTP01, a.challengeHTTPProvider) | ||||
| 	} else { | ||||
| 		return nil, errors.New("ACME challenge not specified, please select HTTP or DNS Challenge") | ||||
| 	} | ||||
|  | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	return client, nil | ||||
| } | ||||
|  | ||||
| func (a *ACME) loadCertificateOnDemand(clientHello *tls.ClientHelloInfo) (*tls.Certificate, error) { | ||||
| 	domain := types.CanonicalDomain(clientHello.ServerName) | ||||
| 	account := a.store.Get().(*Account) | ||||
| 	if certificateResource, ok := account.DomainsCertificate.getCertificateForDomain(domain); ok { | ||||
| 		return certificateResource.tlsCert, nil | ||||
| 	} | ||||
| 	certificate, err := a.getDomainsCertificates([]string{domain}) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	log.Debugf("Got certificate on demand for domain %s", domain) | ||||
|  | ||||
| 	transaction, object, err := a.store.Begin() | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	account = object.(*Account) | ||||
| 	cert, err := account.DomainsCertificate.addCertificateForDomains(certificate, types.Domain{Main: domain}) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	if err = transaction.Commit(account); err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	return cert.tlsCert, nil | ||||
| } | ||||
|  | ||||
| // LoadCertificateForDomains loads certificates from ACME for given domains | ||||
| func (a *ACME) LoadCertificateForDomains(domains []string) { | ||||
| 	a.jobs.In() <- func() { | ||||
| 		log.Debugf("LoadCertificateForDomains %v...", domains) | ||||
|  | ||||
| 		domains, err := a.getValidDomains(domains, false) | ||||
| 		if err != nil { | ||||
| 			log.Errorf("Error getting valid domain: %v", err) | ||||
| 			return | ||||
| 		} | ||||
|  | ||||
| 		operation := func() error { | ||||
| 			if a.client == nil { | ||||
| 				return errors.New("ACME client still not built") | ||||
| 			} | ||||
| 			return nil | ||||
| 		} | ||||
| 		notify := func(err error, time time.Duration) { | ||||
| 			log.Errorf("Error getting ACME client: %v, retrying in %s", err, time) | ||||
| 		} | ||||
| 		ebo := backoff.NewExponentialBackOff() | ||||
| 		ebo.MaxElapsedTime = 30 * time.Second | ||||
| 		err = backoff.RetryNotify(safe.OperationWithRecover(operation), ebo, notify) | ||||
| 		if err != nil { | ||||
| 			log.Errorf("Error getting ACME client: %v", err) | ||||
| 			return | ||||
| 		} | ||||
| 		account := a.store.Get().(*Account) | ||||
|  | ||||
| 		// Check provided certificates | ||||
| 		uncheckedDomains := a.getUncheckedDomains(domains, account) | ||||
| 		if len(uncheckedDomains) == 0 { | ||||
| 			return | ||||
| 		} | ||||
| 		certificate, err := a.getDomainsCertificates(uncheckedDomains) | ||||
| 		if err != nil { | ||||
| 			log.Errorf("Error getting ACME certificates %+v : %v", uncheckedDomains, err) | ||||
| 			return | ||||
| 		} | ||||
| 		log.Debugf("Got certificate for domains %+v", uncheckedDomains) | ||||
| 		transaction, object, err := a.store.Begin() | ||||
|  | ||||
| 		if err != nil { | ||||
| 			log.Errorf("Error creating transaction %+v : %v", uncheckedDomains, err) | ||||
| 			return | ||||
| 		} | ||||
| 		var domain types.Domain | ||||
| 		if len(uncheckedDomains) > 1 { | ||||
| 			domain = types.Domain{Main: uncheckedDomains[0], SANs: uncheckedDomains[1:]} | ||||
| 		} else { | ||||
| 			domain = types.Domain{Main: uncheckedDomains[0]} | ||||
| 		} | ||||
| 		account = object.(*Account) | ||||
| 		_, err = account.DomainsCertificate.addCertificateForDomains(certificate, domain) | ||||
| 		if err != nil { | ||||
| 			log.Errorf("Error adding ACME certificates %+v : %v", uncheckedDomains, err) | ||||
| 			return | ||||
| 		} | ||||
| 		if err = transaction.Commit(account); err != nil { | ||||
| 			log.Errorf("Error Saving ACME account %+v: %v", account, err) | ||||
| 			return | ||||
| 		} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // Get provided certificate which check a domains list (Main and SANs) | ||||
| // from static and dynamic provided certificates | ||||
| func (a *ACME) getProvidedCertificate(domains string) *tls.Certificate { | ||||
| 	log.Debugf("Looking for provided certificate to validate %s...", domains) | ||||
| 	cert := searchProvidedCertificateForDomains(domains, a.TLSConfig.NameToCertificate) | ||||
| 	if cert == nil && a.dynamicCerts != nil && a.dynamicCerts.Get() != nil { | ||||
| 		cert = searchProvidedCertificateForDomains(domains, a.dynamicCerts.Get().(map[string]*tls.Certificate)) | ||||
| 	} | ||||
| 	if cert == nil { | ||||
| 		log.Debugf("No provided certificate found for domains %s, get ACME certificate.", domains) | ||||
| 	} | ||||
| 	return cert | ||||
| } | ||||
|  | ||||
| func searchProvidedCertificateForDomains(domain string, certs map[string]*tls.Certificate) *tls.Certificate { | ||||
| 	// Use regex to test for provided certs that might have been added into TLSConfig | ||||
| 	for certDomains := range certs { | ||||
| 		domainChecked := false | ||||
| 		for _, certDomain := range strings.Split(certDomains, ",") { | ||||
| 			domainChecked = types.MatchDomain(domain, certDomain) | ||||
| 			if domainChecked { | ||||
| 				break | ||||
| 			} | ||||
| 		} | ||||
| 		if domainChecked { | ||||
| 			log.Debugf("Domain %q checked by provided certificate %q", domain, certDomains) | ||||
| 			return certs[certDomains] | ||||
| 		} | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| // Get provided certificate which check a domains list (Main and SANs) | ||||
| // from static and dynamic provided certificates | ||||
| func (a *ACME) getUncheckedDomains(domains []string, account *Account) []string { | ||||
| 	log.Debugf("Looking for provided certificate to validate %s...", domains) | ||||
| 	allCerts := make(map[string]*tls.Certificate) | ||||
|  | ||||
| 	// Get static certificates | ||||
| 	for domains, certificate := range a.TLSConfig.NameToCertificate { | ||||
| 		allCerts[domains] = certificate | ||||
| 	} | ||||
|  | ||||
| 	// Get dynamic certificates | ||||
| 	if a.dynamicCerts != nil && a.dynamicCerts.Get() != nil { | ||||
| 		for domains, certificate := range a.dynamicCerts.Get().(map[string]*tls.Certificate) { | ||||
| 			allCerts[domains] = certificate | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	// Get ACME certificates | ||||
| 	if account != nil { | ||||
| 		for domains, certificate := range account.DomainsCertificate.toDomainsMap() { | ||||
| 			allCerts[domains] = certificate | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	// Get Configuration Domains | ||||
| 	for i := 0; i < len(a.Domains); i++ { | ||||
| 		allCerts[a.Domains[i].Main] = &tls.Certificate{} | ||||
| 		for _, san := range a.Domains[i].SANs { | ||||
| 			allCerts[san] = &tls.Certificate{} | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return searchUncheckedDomains(domains, allCerts) | ||||
| } | ||||
|  | ||||
| func searchUncheckedDomains(domains []string, certs map[string]*tls.Certificate) []string { | ||||
| 	var uncheckedDomains []string | ||||
| 	for _, domainToCheck := range domains { | ||||
| 		if !isDomainAlreadyChecked(domainToCheck, certs) { | ||||
| 			uncheckedDomains = append(uncheckedDomains, domainToCheck) | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if len(uncheckedDomains) == 0 { | ||||
| 		log.Debugf("No ACME certificate to generate for domains %q.", domains) | ||||
| 	} else { | ||||
| 		log.Debugf("Domains %q need ACME certificates generation for domains %q.", domains, strings.Join(uncheckedDomains, ",")) | ||||
| 	} | ||||
| 	return uncheckedDomains | ||||
| } | ||||
|  | ||||
| func (a *ACME) getDomainsCertificates(domains []string) (*Certificate, error) { | ||||
| 	domains = fun.Map(types.CanonicalDomain, domains).([]string) | ||||
| 	log.Debugf("Loading ACME certificates %s...", domains) | ||||
| 	bundle := true | ||||
| 	certificate, failures := a.client.ObtainCertificate(domains, bundle, nil, OSCPMustStaple) | ||||
| 	if len(failures) > 0 { | ||||
| 		log.Error(failures) | ||||
| 		return nil, fmt.Errorf("cannot obtain certificates %+v", failures) | ||||
| 	} | ||||
| 	log.Debugf("Loaded ACME certificates %s", domains) | ||||
| 	return &Certificate{ | ||||
| 		Domain:        certificate.Domain, | ||||
| 		CertURL:       certificate.CertURL, | ||||
| 		CertStableURL: certificate.CertStableURL, | ||||
| 		PrivateKey:    certificate.PrivateKey, | ||||
| 		Certificate:   certificate.Certificate, | ||||
| 	}, nil | ||||
| } | ||||
|  | ||||
| func (a *ACME) runJobs() { | ||||
| 	safe.Go(func() { | ||||
| 		for job := range a.jobs.Out() { | ||||
| 			function := job.(func()) | ||||
| 			function() | ||||
| 		} | ||||
| 	}) | ||||
| } | ||||
|  | ||||
| // getValidDomains checks if given domain is allowed to generate a ACME certificate and return it | ||||
| func (a *ACME) getValidDomains(domains []string, wildcardAllowed bool) ([]string, error) { | ||||
| 	if len(domains) == 0 || (len(domains) == 1 && len(domains[0]) == 0) { | ||||
| 		return nil, errors.New("unable to generate a certificate when no domain is given") | ||||
| 	} | ||||
|  | ||||
| 	if strings.HasPrefix(domains[0], "*") { | ||||
| 		if !wildcardAllowed { | ||||
| 			return nil, fmt.Errorf("unable to generate a wildcard certificate for domain %q from a 'Host' rule", strings.Join(domains, ",")) | ||||
| 		} | ||||
|  | ||||
| 		if a.DNSChallenge == nil && len(a.DNSProvider) == 0 { | ||||
| 			return nil, fmt.Errorf("unable to generate a wildcard certificate for domain %q : ACME needs a DNSChallenge", strings.Join(domains, ",")) | ||||
| 		} | ||||
|  | ||||
| 		if len(domains) > 1 { | ||||
| 			return nil, fmt.Errorf("unable to generate a wildcard certificate for domain %q : SANs are not allowed", strings.Join(domains, ",")) | ||||
| 		} | ||||
| 	} else { | ||||
| 		for _, san := range domains[1:] { | ||||
| 			if strings.HasPrefix(san, "*") { | ||||
| 				return nil, fmt.Errorf("unable to generate a certificate in ACME provider for domains %q: SANs can not be a wildcard domain", strings.Join(domains, ",")) | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	domains = fun.Map(types.CanonicalDomain, domains).([]string) | ||||
| 	return domains, nil | ||||
| } | ||||
|  | ||||
| func isDomainAlreadyChecked(domainToCheck string, existentDomains map[string]*tls.Certificate) bool { | ||||
| 	for certDomains := range existentDomains { | ||||
| 		for _, certDomain := range strings.Split(certDomains, ",") { | ||||
| 			if types.MatchDomain(domainToCheck, certDomain) { | ||||
| 				return true | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| 	return false | ||||
| } | ||||
|  | ||||
| // deleteUnnecessaryDomains deletes from the configuration : | ||||
| // - Duplicated domains | ||||
| // - Domains which are checked by wildcard domain | ||||
| func (a *ACME) deleteUnnecessaryDomains() { | ||||
| 	var newDomains []types.Domain | ||||
|  | ||||
| 	for idxDomainToCheck, domainToCheck := range a.Domains { | ||||
| 		keepDomain := true | ||||
|  | ||||
| 		for idxDomain, domain := range a.Domains { | ||||
| 			if idxDomainToCheck == idxDomain { | ||||
| 				continue | ||||
| 			} | ||||
|  | ||||
| 			if reflect.DeepEqual(domain, domainToCheck) { | ||||
| 				if idxDomainToCheck > idxDomain { | ||||
| 					log.Warnf("The domain %v is duplicated in the configuration but will be process by ACME only once.", domainToCheck) | ||||
| 					keepDomain = false | ||||
| 				} | ||||
| 				break | ||||
| 			} else if strings.HasPrefix(domain.Main, "*") && domain.SANs == nil { | ||||
| 				// Check if domains can be validated by the wildcard domain | ||||
|  | ||||
| 				var newDomainsToCheck []string | ||||
|  | ||||
| 				// Check if domains can be validated by the wildcard domain | ||||
| 				domainsMap := make(map[string]*tls.Certificate) | ||||
| 				domainsMap[domain.Main] = &tls.Certificate{} | ||||
|  | ||||
| 				for _, domainProcessed := range domainToCheck.ToStrArray() { | ||||
| 					if isDomainAlreadyChecked(domainProcessed, domainsMap) { | ||||
| 						log.Warnf("Domain %q will not be processed by ACME because it is validated by the wildcard %q", domainProcessed, domain.Main) | ||||
| 						continue | ||||
| 					} | ||||
| 					newDomainsToCheck = append(newDomainsToCheck, domainProcessed) | ||||
| 				} | ||||
|  | ||||
| 				// Delete the domain if both Main and SANs can be validated by the wildcard domain | ||||
| 				// otherwise keep the unchecked values | ||||
| 				if newDomainsToCheck == nil { | ||||
| 					keepDomain = false | ||||
| 					break | ||||
| 				} | ||||
| 				domainToCheck.Set(newDomainsToCheck) | ||||
| 			} | ||||
| 		} | ||||
|  | ||||
| 		if keepDomain { | ||||
| 			newDomains = append(newDomains, domainToCheck) | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	a.Domains = newDomains | ||||
| } | ||||
| @@ -1,43 +0,0 @@ | ||||
| { | ||||
|   "Email": "test@traefik.io", | ||||
|   "Registration": { | ||||
|     "body": { | ||||
|       "resource": "reg", | ||||
|       "id": 3, | ||||
|       "key": { | ||||
|         "kty": "RSA", | ||||
|         "n": "y5a71suIqvEtovDmDVQ3SSNagk5IVCFI_TvqWpEXSrdbcDE2C-PTEtEUJuLkYwygcpiWYbPmXgdS628vQCw5Uo4DeDyHiuysJOWBLaWow3p9goOdhnPbGBq0liIR9xXyRoctdipVk8UiO9scWsu4jMBM3sMr7_yBWPfYYiLEQmZGFO3iE7Oqr55h_kncHIj5lUQY1j_jkftqxlxUB5_0quyJ7l915j5QY--eY7h4GEhRvx0TlUpi-CnRtRblGeDDDilXZD6bQN2962WdKecsmRaYx-ttLz6jCPXz2VDJRWNcIS501ne2Zh3hzw_DS6IRd2GIia1Wg4sisi9epC9sumXPHi6xzR6-_i_nsFjdtTkUcV8HmorOYoc820KQVZaLScxa8e7-ixpOd6mr6AIbEf7dBAkb9f_iK3GwpqKD8yNcaj1EQgNSyJSjnKSulXI_GwkGnuXe00Qpb1a8ha5Z8yWg7XmZZnJyAZrmK60RfwRNQ1rO5ioerNUBJ2KYTYNzVjBdob9Ug6Cjh4bEKNNjqcbjQ50_Z97Vw40xzpDQ_fYllc6n92eSuv6olxFJTmK7EhHuanDzITngaqei3zL9RwQ7P-1jfEZ03qmGrQYYqXcsS46PQ8cE-frzY2mKp16pRNCG7-03gKVGV0JHyW1aYbevNUk7OumCAXhC2YOigBk", | ||||
|         "e": "AQAB" | ||||
|       }, | ||||
|       "contact": [ | ||||
|         "mailto:test@traefik.io" | ||||
|       ], | ||||
|       "agreement": "http://boulder:4000/terms/v1" | ||||
|     }, | ||||
|     "uri": "http://127.0.0.1:4000/acme/reg/3", | ||||
|     "new_authzr_uri": "http://127.0.0.1:4000/acme/new-authz", | ||||
|     "terms_of_service": "http://boulder:4000/terms/v1" | ||||
|   }, | ||||
|   "PrivateKey": "MIIJJwIBAAKCAgEAy5a71suIqvEtovDmDVQ3SSNagk5IVCFI/TvqWpEXSrdbcDE2C+PTEtEUJuLkYwygcpiWYbPmXgdS628vQCw5Uo4DeDyHiuysJOWBLaWow3p9goOdhnPbGBq0liIR9xXyRoctdipVk8UiO9scWsu4jMBM3sMr7/yBWPfYYiLEQmZGFO3iE7Oqr55h/kncHIj5lUQY1j/jkftqxlxUB5/0quyJ7l915j5QY++eY7h4GEhRvx0TlUpi+CnRtRblGeDDDilXZD6bQN2962WdKecsmRaYx+ttLz6jCPXz2VDJRWNcIS501ne2Zh3hzw/DS6IRd2GIia1Wg4sisi9epC9sumXPHi6xzR6+/i/nsFjdtTkUcV8HmorOYoc820KQVZaLScxa8e7+ixpOd6mr6AIbEf7dBAkb9f/iK3GwpqKD8yNcaj1EQgNSyJSjnKSulXI/GwkGnuXe00Qpb1a8ha5Z8yWg7XmZZnJyAZrmK60RfwRNQ1rO5ioerNUBJ2KYTYNzVjBdob9Ug6Cjh4bEKNNjqcbjQ50/Z97Vw40xzpDQ/fYllc6n92eSuv6olxFJTmK7EhHuanDzITngaqei3zL9RwQ7P+1jfEZ03qmGrQYYqXcsS46PQ8cE+frzY2mKp16pRNCG7+03gKVGV0JHyW1aYbevNUk7OumCAXhC2YOigBkCAwEAAQKCAgA8XW1EuwTC6tAFSDhuK1JZNUpY6K05hMUHkQRj5jFpzgQmt/C2hc7H/YZkIVJmrA/G6sdsINNlffZwKH9yH6q/d6w/snLeFl7UcdhjmIL5sxAT6sKCY0fLVd/FxERfZvp3Pw2Tw+mr7v+/j7BQm6cU1M/2HRiiB9SydIqMTpKyvXB6NC6ceOFbQTL9GxlQvKyEPbS/kiH/3vRB7I5d1GfPZmNfcp6ark9X0my8VK4HRSo36H8t/OhrfLrZXvh/O82aHVf0OTv/d8AgU/jNu+XVXoXegUfWglQFDChJf1KuaE+g5w1tqgFDNgkGRD475soXA6xgZi0Iw/B9tN3zALzT4IiAW1q72feeTgKOMA2zGtKXxQZZSOV+DuWFZNz/tT7XqGQThqxM09CHv2WGOe80vobtegXYTUt90hysrqIZmBW5XYdzQlJh1KWTtfCaTrWd47kbGvhkEPc8aA3Ji4/AqfkVXiqwaLu+MSlgzPpRj7U7UAIDqnpZjgttgLp74Ujnk3bTaUzdyyNqYDBG3IFGr/Sv+2GQDAUn/PYRJKWr0BteqOzX9zvW3zY8g9CYVXfK/AW3RMWLV8ly6vH/gWqa9gEuzRNRlzjUU6/HCVbUx3UT8RMWH2TQ0uuQZr5JX1iTwjeeT0dEIly1NnRQC92wcrE4UUTBEF3krGVpDBf0AQKCAQEA4jB8w+2fwzbF8X+gCODcY7sTeJRunzGy+jbdaLkcThuylga+6W3ZgWx0BD30ql9K2mouCVu86fCTnBeXXEC3QoTdgw/EzJ83+4JU3QSDdzs9Ta9vLHyvrpUkQfZ8UZpeLLmFsmsBMbBbnfw0S1TzXDsgrAc+G4tia8nO/Iqu75kEMGzmHQAvmN3iSqc1aTS4qumbB19g+v+csq9NEht4F9jt39KotG+OD3MxCxtMu7vxAkJRjFFcgcbb2Rtqe/kQEKA1vLEAJg27lV4k8XibCSerVUR6IzT8WZHrNiXmpRguTLl2k8uFUdCOOx6aLGyRVJ6+8SgIsMR540vnxwQzEQKCAQEA5mu2wtWT19mvXopC3easPsXIPzc5oaRkqfWZYT1KHcVQ7NIXsE3vCjcf/3igZ8l/FVQ4G4fpk/GoTqlpV5Aq/JHCpVOR2O69uB+W4kWgliejpHvF9gszzAYnC8lIXqDbWiinBhmm3ii8sDGAoBaSDw5NMUq3mI+nd8zZ+jx1bLBczDafmQ0YKr8k0YaROxIgoBgDOQDdSqG387lwzpza2DKI5Al3HfS42zjT0RmBahPiuT2aEoUZmIYuvFY0fEjfkpbdvLyexHfZCILRUGlG1nAwASFg86lp+mFSBJ3E3cvbP0CpbFGxon5u4Ao3/7htoOh6huh7MQ91h41fv1hsiQKCAQAe7WRR4e7jYVzlbX7zV9Oqq0y5QwpxJ/mB7viNNiphn7Xmf5uhDU0dPjgK0HHgzdDNVpFe5DVLg4KbaDpg+dRU+xfSsNhG5kpgUGzMH67eIbJ7Kc64tX/MDkZ74nkTK1lPIjrer3TlV2jfjDmWR1JTPR51hzP9ziwx8tEjhM7woeqJuIoqUvkvHL+xV3WdIgFSFUkGVAtNpp/FauTN4gWktRupbAN3UH2LLUP6ccwnK0aD+Y9u8T0F3av33qDLvL1umIlgeI89pMkOXmYMwmHoeY0axpcwszECCkqwB7SmxEyoXv+Qq9ZZ3ntkKAYKpvmkKWSQUtoFWYgVBS727mMRAoIBABLdwusU/bPwuPEutObiWjwRiaHTbb6UbUGVQGe70vO5EjUxxorC9s2JUe9i+w9EakleyfFHIZLheHxoVp26yio/7QYIX6q5cYM/4uTH+qwQts9i6wSISkdsQYovguNsnEk3huVy+Dy8bSaoBvYUowTkkOF2Uq4FJRskBLz+ckbh8dcuqcaoUdA+Mk+NixqhE1bIYIssTPItZ5hnGJtyMGD/UkIJnF0ximk4r+8w/W2oDypHpvPZPg1E/1KgZE/Az7166NDpSL6haX3O6ECDPi+Uo/mTuBJ7TpgXm9WQ7WuTo3H8Y2LhFYBOhdmGPKuNeDxyjIW7R0rvDxp4MtzB6rECggEAJIl7/qp1lxUQPQJRTsEYBkOtdRw0IGG1Rcj0emhHaBN05c9opCy+Osb7mVeU5ZiULe5kD02phL+36pEumprz7QzN46Y5pZc8AQ2W/QkeL4Wo9U9QzczvQQzc1EqrBkzvQTZtBhn4DRzz0IuTn1beVyHtBZeNpBFgMQFv9VYQuUNwFoTOkkQrBRnYbXH6KEnhF3c/1Hzi4KHVdHdfZ3LH7KFQJ34xio0q2tWQSQYeybmwOXdd9sxpz/Y4KBS9fqm7UrwnPK8yuOc05HLEaws+1iam5YyJprlQo3mGKe0wRztwn44HDeQr70LlFm0lzigVAv0hSiWO1Q5hJL7nDu8m/Q==", | ||||
|   "DomainsCertificate": { | ||||
|     "Certs": [ | ||||
|       { | ||||
|         "Domains": { | ||||
|           "Main": "local1.com", | ||||
|           "SANs": [ | ||||
|             "test1.local1.com", | ||||
|             "test2.local1.com" | ||||
|           ] | ||||
|         }, | ||||
|         "Certificate": { | ||||
|           "Domain": "local1.com", | ||||
|           "CertURL": "http://127.0.0.1:4000/acme/cert/ffc4f3f14def9ee6ec6a0522b5c0baa3379d", | ||||
|           "CertStableURL": "", | ||||
|           "PrivateKey": "LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlKS1FJQkFBS0NBZ0VBdVNoTTR4enF6cE5YcFNaNnAvZnQrRmt5VmgyK1BSZXJUelV0OERRSng2UkVjQS9FCnN2RnNIVmNOSkZMS2twYTNlOEd3SUZBakJQNnJPK3hoR1JjWlJrdENON1gyOW5LZFhGbHZkYzJxd0hyTFF5WWkKTTB3ODhTck41VERiNi96TWU2dTB0dERiYWtDbDd6ZEJKUXJ6a1h5ZU1MeVkzTUs3aVkrMHpwL2JqMVhvbk5DdQpaQStkZ3hsMVNrV01DVUYvQk9HNWFyT1hwb0x4S0dQWGdzV3hOTVNLVmJKSHczL3ZqNTViZU92Um5lT3BNWlhvCmMwOWpZT3VBakNka1Z5czBSWHJLNWNCRDRMbVRXdnN4MFdTK2VMVHlGTTdQTHVZM3lEWkNNWEhjVmlqRHhnbFMKYjB1ZVRQcGFUWEQwYkxqZ0RNOUVEdE15ZEJzMUNPWlpPWG9ickN5Q2I1eWxTOFdVd1NzVXM1UldxZnlVbnAvcgpSNGx2c2RZOWRVZjRPdkNMVnJvWWk5NWFGc1Zxa0xLOExuL0Eyc3kxYWlDTnR4RmpKOXRXbWU0V0NhdzRoU0YvCkR4NWVNNWNYR2JSYXduVlZJQlZXeHhzNTBPMFJlUWRvbXBQZEFNS1RDWk9SRmxYaDdOWTdxQVdWRGtpdzhyam8Kekd3Ni9XdjlOR3hTNTliKzc0YVAxcjBxOTZ2RS9Rdi8zTCtjbjhiN0lBLytPYmFKdzhIT3RGbXc4RjBxQkN3MAprYWVVSloxb1JueGFYQUo4RHhHREpFOVdNUzh0QmJtVm16YkxoRkMzeDdVc0xGeTBrSzh1SFBFT3dQb2NKNUFUCkE1UHBvclNEMmFleHA0Z3VqYVp5c1JManpmY0dnaTdva0JFNlZVNWVqRE1iYS9lNERQNEJQUVg5VmtVQ0F3RUEKQVFLQ0FnQmZjMWdYcUp1ZmZMT3REcVlpbXh4UmIrSVVKT2NpWldaSndmZDVvY244NGtEcHFDZFZ2RUZvNnF4NgpzamQ5MURhb2xOUHdCSC9aSGxRMTR3aTNQNEluQzdzS0wwTXVEeTN5SXFUa0RPOWVwSzdPWWdVMWZyTFgvS0lCCjZlc2x2Ny9HYldFTzhhSjdKdktqM0U4NEFtcEg4UDgzenJIYTlJUnJTT3NEcmNNcEpEZHpSOXp1OW1IVDZMYmYKWC9UdC9KYTNkSW42YUxUZ0FSYkRKSjAvN0J3TFFOcXpqT0dUOWdzUWRhbGdMK2x5eEo4L1ViRndhRmVwNmgzdApvbzBHcHQ0ZWgwdTdueDhlNVd3Q2RnWmJsTnpnS3grMC9Gd3dLRHhQZVRFc2ZpOEJONmlkR2NjbVdzd3prTWdtCnJmbERaeGNSWTNRSlZIVHBCL0dTTWZXRFBPQ3dRdGltQk1WN3kxM2hPMTdPWXpSNDBMZnpUalJBbmtna2V2eWYKcFowb3dLR3o4QS9haHhRWWJmYVQ5VEhXV0wrYUpYeUhFanBKckp5aTg3UExVbzhsOFVydU56MDRWNXpLOFJPbgo2cG9EWmVtbm1EYWRlU09pK3hZRWlGT1NwSXNWbzlpcm9jUGFKN2YzYWpiNUU4RHpuN1o1MmhzL2R6akpLcFZJCm5mVDFkUU9SZEowSXRUNlRlQ2RTL0dpS25IS1RtNjR2T21IbmlJcm8rUGRhUmFjV0IrTUJ0VytRd0cyUStyRGkKc3g4NlpQbHRpTVpLMDZ5TVlyVHZUdGk2aFVGaUY5cWh4b3RGazdNQkNrZlIwYUVhaUREQUpKNm1jb1lpRUQ2QgpBVGJhVmpVaGNaUiswYkRST25PN0ozRk5rZmx3K2dMaVhvcXFRRW9pU2ZWb2h5SWY3UUtDQVFFQThjYTM5K0g4CjN3L2Qrcm0yUGNhM0RMQnBYaWU4Z3ZYcGpjazVYSkpvSGVmbnJjZWQrcFpXaTZEYncwYld0MEdtYkxmVjJNSlAKV2I1aTZzSXhmdkN3YlFqbHY0UnExMVA5ZEswT3poMnVpKzZ6cXVBMG5YTVcrN0lJS0cvdDhmS2NJZGRRNnRGcwpFclFVTFBDak56ODA2cHBiSlhPRmVvMW1BK293TGhHNlA3dDhCdlZHSk1NaTNxejNlSUNuVVE2eDNFY01ITXNuClhrM21DUzI1WUZaNk96cytFK254cGVraTAzZmQwblp3UE1jdElHZys1c3hleE9zREsrTHlvb2FqQnc5N0oyUzIKcUNNWXFtT0tLcmxEQ3Y1WmQ4dlZLN3hXVmpKRVhGTTNMZ2pieHBRcCtuVXNVVWxwS01LOVlGS0lRREl0RU9aMApWcWExTXJaOElzN1l5d0tDQVFFQXhBemZIa2pIVGlvTHdZbG5EcEk0MWlOTDh5Y0ZBallrTC94dWhPU2tlVkE4CjdRWDZPZUpDekR3Z0FUYXVqOWR6Y0wwby9yTndWV0xWcnQ3OXk3YnJvVDdFREZKWVNTY25GRXNMTlVWSXRncGkKckNSUXJTL1F2TkVGTmE5K0pRc1dmYkdBNHdIUTFaSjI4MFp1cWMvNlEyUi9kZVh3cUZBQVBHN2NIcEhHWlR6ZQoyRmFRUHFLRkV4WlEyZkpvRys0SVBRNHVQVERybXlGMmVUWXk2T3BaaDBHbWJRYlVTa1dFWDlQRmF1cHJIWVdGCk8wK25DaVVPNVRaMFZoaGR2dUNKMWdPclZHYzhBUlJtUVZ1aUNEWTZCaGlvVTU0ZmZsSXlDTXZ5a3MwcmRXZ3MKWVJ2TmN4TXNlRGJpTDRKSURkMHhiN1d4VUdmVjRVNHZPMks5Vms1N0x3S0NBUUVBMkd1eE1jcXd1RnRUc0tPYwpaaUFDcXZFZTRKRmhSVGtySHlnSW1MelZSaS9ZU3M1c3MycnZmWDA0T3N5bVZ0UUZUVHdoeUMzbktjWXFkVW52ClZGblBFMHJyblV2Qzk0elBUQ205SHZPaTBzK1JORndOdlFMUWgrME5NR1ZBOFZyaU44aXRQZ1RJWU5XaFdianQKNFA1TE45V0QwVHBmT1J4cFBRZmNxT0JsZjdjcmhtNzNvdUNwemZtMmE3OStCaWpKUFF5NzR1cFhDeXRmeHNlUApNSlU0Uk56NjdJaDFMclpKM2xGbDFvYitZT2xKazhDOHpZd1RLT0hWck9zeGxobyt4SXN2Q2t3MDFMelZ6Mi9hCnRmT3Y5NTlHSnQzbXE0ZWpJUFZPQy9iUlpmdTMvMEdSY2dpQTZ5SnpaM0VxWTVaOU1EbTU3VzdjcE5RRlRxZmEKNXEyUmtRS0NBUUErNGhZSzQ3TXg2aUNkTWxKaEJSdS82OUJucktOWm96NFdPalRFNFlXejk3MmpGU0Mrd2tsRQpzeUJjNDBvNGp4WFRHb2wwc04rZU03WndnY3dNTko3OXVHRXZ4cFhVMlA4YTdqc3BHaEVKZXVsTlo5U015R0orCnZkaWE4TEJZZDJiK2FCbjhOay9pd1Rqd0xTNC92NXI1Vk5uaFdpRElDK2tYZVVPWGRwQ1pWbDN3TEV2V0cxRHQKMzJHTmxzZzM5VENsVE5BZUJudjc1VTdYOEQrQ0gvRVpoa0E0aGxFL2hXN0JRZTczclRzd1creHhLc3BjWWFpVwpjdEg3NzVMYUw3Rm1lUVRTYk01OVZpcTZXZ2J0OVY3Rko5R09DSkQzZHF2ZjBITDlEVndjSzQ3WWt3OWlFc3RYCnY5cnEvREhhYUpGNzBGNlFlTTNNbDhSa212WTZJYkEzQW9JQkFRRGt6RmZLeG9HQ3dWUDlua3k4NmFQSjFvd2kKc2FDZEx6RjRWTENRZzkrUXJITzEyY0p5MFFQUnJ2cUQyMGp1cDFlOWJhWVZzbkdYc1FZTFg2NVR6UzJSSCtlSAp6S0NPTTdnMVE3djMxNWpjMDMvN1lQck4rb3RrV0VBOUkyaDZjUE1vY3c0aERTNk02OFlxQVlKTS9RclVhenZhCnhBTFJaZEVkQW1xWDA4VHhuY1hRUEVxYkk0ZnlSZ2pVM1BYR3RRaFFFbERpR2kwbThjQTJNTXdsR1RmbTdOSXgKaENjZ2ZkL296TEp2VUhiMkxLRi82cXEySmJVRHlOMkVoK0xSZUJjdnp6Y1grZE5MdGQxY0Uvcm1SM2hMbWxmNgo3KzRpTVMxK0t1eWV3VlJVUEE1c1F1aUYyVUVoeEs1MUpZK1FpOG9HbERKdGRrOXB3QlZNN1F0WW9KVEwKLS0tLS1FTkQgUlNBIFBSSVZBVEUgS0VZLS0tLS0K", | ||||
|           "Certificate": "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUZvakNDQklxZ0F3SUJBZ0lUQVAvRTgvRk43NTdtN0dvRklyWEF1cU0zblRBTkJna3Foa2lHOXcwQkFRc0YKQURBZk1SMHdHd1lEVlFRRERCUm9NbkJ3ZVNCb01tTnJaWElnWm1GclpTQkRRVEFlRncweE9EQXhNVFV3TnpJNQpNREJhRncweE9EQTBNVFV3TnpJNU1EQmFNRVF4RXpBUkJnTlZCQU1UQ214dlkyRnNNUzVqYjIweExUQXJCZ05WCkJBVVRKR1ptWXpSbU0yWXhOR1JsWmpsbFpUWmxZelpoTURVeU1tSTFZekJpWVdFek16YzVaRENDQWlJd0RRWUoKS29aSWh2Y05BUUVCQlFBRGdnSVBBRENDQWdvQ2dnSUJBTGtvVE9NYzZzNlRWNlVtZXFmMzdmaFpNbFlkdmowWApxMDgxTGZBMENjZWtSSEFQeExMeGJCMVhEU1JTeXBLV3QzdkJzQ0JRSXdUK3F6dnNZUmtYR1VaTFFqZTE5dlp5Cm5WeFpiM1hOcXNCNnkwTW1Jak5NUFBFcXplVXcyK3Y4ekh1cnRMYlEyMnBBcGU4M1FTVUs4NUY4bmpDOG1OekMKdTRtUHRNNmYyNDlWNkp6UXJtUVBuWU1aZFVwRmpBbEJmd1RodVdxemw2YUM4U2hqMTRMRnNUVEVpbFd5UjhOLwo3NCtlVzNqcjBaM2pxVEdWNkhOUFkyRHJnSXduWkZjck5FVjZ5dVhBUStDNWsxcjdNZEZrdm5pMDhoVE96eTdtCk44ZzJRakZ4M0ZZb3c4WUpVbTlMbmt6NldrMXc5R3k0NEF6UFJBN1RNblFiTlFqbVdUbDZHNndzZ20rY3BVdkYKbE1FckZMT1VWcW44bEo2ZjYwZUpiN0hXUFhWSCtEcndpMWE2R0l2ZVdoYkZhcEN5dkM1L3dOck10V29namJjUgpZeWZiVnBudUZnbXNPSVVoZnc4ZVhqT1hGeG0wV3NKMVZTQVZWc2NiT2REdEVYa0hhSnFUM1FEQ2t3bVRrUlpWCjRleldPNmdGbFE1SXNQSzQ2TXhzT3Yxci9UUnNVdWZXL3UrR2o5YTlLdmVyeFAwTC85eS9uSi9HK3lBUC9qbTIKaWNQQnpyUlpzUEJkS2dRc05KR25sQ1dkYUVaOFdsd0NmQThSZ3lSUFZqRXZMUVc1bFpzMnk0UlF0OGUxTEN4Ywp0SkN2TGh6eERzRDZIQ2VRRXdPVDZhSzBnOW1uc2FlSUxvMm1jckVTNDgzM0JvSXU2SkFST2xWT1hvd3pHMnYzCnVBeitBVDBGL1ZaRkFnTUJBQUdqZ2dHd01JSUJyREFPQmdOVkhROEJBZjhFQkFNQ0JhQXdIUVlEVlIwbEJCWXcKRkFZSUt3WUJCUVVIQXdFR0NDc0dBUVVGQndNQ01Bd0dBMVVkRXdFQi93UUNNQUF3SFFZRFZSME9CQllFRk5LZQpBVUZYc2Z2N2lML0lYVVBXdzY2ZU5jQnhNQjhHQTFVZEl3UVlNQmFBRlB0NFR4TDVZQldETEo4WGZ6UVpzeTQyCjZrR0pNR1lHQ0NzR0FRVUZCd0VCQkZvd1dEQWlCZ2dyQmdFRkJRY3dBWVlXYUhSMGNEb3ZMekV5Tnk0d0xqQXUKTVRvME1EQXlMekF5QmdnckJnRUZCUWN3QW9ZbWFIUjBjRG92THpFeU55NHdMakF1TVRvME1EQXdMMkZqYldVdgphWE56ZFdWeUxXTmxjblF3T1FZRFZSMFJCREl3TUlJS2JHOWpZV3d4TG1OdmJZSVFkR1Z6ZERFdWJHOWpZV3d4CkxtTnZiWUlRZEdWemRESXViRzlqWVd3eExtTnZiVEFuQmdOVkhSOEVJREFlTUJ5Z0dxQVloaFpvZEhSd09pOHYKWlhoaGJYQnNaUzVqYjIwdlkzSnNNR0VHQTFVZElBUmFNRmd3Q0FZR1o0RU1BUUlCTUV3R0F5b0RCREJGTUNJRwpDQ3NHQVFVRkJ3SUJGaFpvZEhSd09pOHZaWGhoYlhCc1pTNWpiMjB2WTNCek1COEdDQ3NHQVFVRkJ3SUNNQk1NCkVVUnZJRmRvWVhRZ1ZHaHZkU0JYYVd4ME1BMEdDU3FHU0liM0RRRUJDd1VBQTRJQkFRQ3A0Q2FxZlR4THNQTzQKS2JueDJZdEc4bTN3MC9keTVVR1VRNjZHbGxPVTk0L2I0MmNhbTRuNUZrTWlpZ01IaUx4c2JZVXh0cDZKQ3R5cQpLKzFNcDFWWEtSTTVKbFBTNWRIaWhxdHk1U3BrTUhjampwQSs3U2YyVWtoNmpKRWYxTUVJY2JnWnpJRk5IT0hYClVUUUppVFhKcno3blJDZnlQWFZtbWErUGtIRlU4R0VEVzJGOVptU1kzVFBiQWhiWkV2UkZubjUrR1lxbkZuancKWWw3Y0I2MXYwRzVpOGQwbnVvbTB4a2hiNTU3Y3BiZHhLblhsaFU4N2RZSTR5SUdPdUFGUWpYcXFXN2NIZCtXUQpWSDB2dFA3cEgrRmt2YnY4WkkxMHMrNU5ZcCtzZjFQZGQxekJsRmdNSGF3dnFFYUg3SU9sejdkajlCdmtVc0dpClhxQWVqQnFPCi0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0KLS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUVpakNDQTNLZ0F3SUJBZ0lDRWswd0RRWUpLb1pJaHZjTkFRRUxCUUF3S3pFcE1DY0dBMVVFQXd3Z1kyRmoKYTJ4cGJtY2dZM0o1Y0hSdlozSmhjR2hsY2lCbVlXdGxJRkpQVDFRd0hoY05NVFV4TURJeE1qQXhNVFV5V2hjTgpNakF4TURFNU1qQXhNVFV5V2pBZk1SMHdHd1lEVlFRREV4Um9ZWEJ3ZVNCb1lXTnJaWElnWm1GclpTQkRRVENDCkFTSXdEUVlKS29aSWh2Y05BUUVCQlFBRGdnRVBBRENDQVFvQ2dnRUJBTUlLUjNtYUJjVVNzbmNYWXpRVDEzRDUKTnIrWjNtTHhNTWgzVFVkdDZzQUNtcWJKMGJ0UmxnWGZNdE5MTTJPVTFJNmEzSnUrdElaU2RuMnYyMUpCd3Z4VQp6cFpRNHp5MmNpbUlpTVFEWkNRSEp3ekM5R1puOEhhVzA5MWl6OUgwR28zQTdXRFh3WU5tc2RMTlJpMDBvMTRVCmpvYVZxYVBzWXJaV3ZSS2FJUnFhVTBoSG1TMEFXd1FTdk4vOTNpTUlYdXlpd3l3bWt3S2JXbm54Q1EvZ3NjdEsKRlV0Y05yd0V4OVdnajZLbGh3RFR5STFRV1NCYnhWWU55VWdQRnpLeHJTbXdNTzB5TmZmN2hvK1FUOXg1K1kvNwpYRTU5UzRNYzRaWHhjWEtldy9nU2xOOVU1bXZUK0QyQmhEdGtDdXBkZnNaTkNRV3AyN0ErYi9EbXJGSTlOcXNDCkF3RUFBYU9DQWNJd2dnRytNQklHQTFVZEV3RUIvd1FJTUFZQkFmOENBUUF3UXdZRFZSMGVCRHd3T3FFNE1BYUMKQkM1dGFXd3dDb2NJQUFBQUFBQUFBQUF3SW9jZ0FBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQQpBQUFBQUFBd0RnWURWUjBQQVFIL0JBUURBZ0dHTUg4R0NDc0dBUVVGQndFQkJITXdjVEF5QmdnckJnRUZCUWN3CkFZWW1hSFIwY0RvdkwybHpjbWN1ZEhKMWMzUnBaQzV2WTNOd0xtbGtaVzUwY25WemRDNWpiMjB3T3dZSUt3WUIKQlFVSE1BS0dMMmgwZEhBNkx5OWhjSEJ6TG1sa1pXNTBjblZ6ZEM1amIyMHZjbTl2ZEhNdlpITjBjbTl2ZEdOaAplRE11Y0Rkak1COEdBMVVkSXdRWU1CYUFGT21rUCs2ZXBlYnkxZGQ1WUR5VHBpNGtqcGVxTUZRR0ExVWRJQVJOCk1Fc3dDQVlHWjRFTUFRSUJNRDhHQ3lzR0FRUUJndDhUQVFFQk1EQXdMZ1lJS3dZQkJRVUhBZ0VXSW1oMGRIQTYKTHk5amNITXVjbTl2ZEMxNE1TNXNaWFJ6Wlc1amNubHdkQzV2Y21jd1BBWURWUjBmQkRVd016QXhvQytnTFlZcgphSFIwY0RvdkwyTnliQzVwWkdWdWRISjFjM1F1WTI5dEwwUlRWRkpQVDFSRFFWZ3pRMUpNTG1OeWJEQWRCZ05WCkhRNEVGZ1FVKzNoUEV2bGdGWU1zbnhkL05CbXpMamJxUVlrd0RRWUpLb1pJaHZjTkFRRUxCUUFEZ2dFQkFBMFkKQWVMWE9rbHg0aGhDaWtVVWwrQmRuRmZuMWcwVzVBaVFMVk5JT0w2UG5xWHUwd2puaE55aHFkd25maFlNbm95NAppZFJoNGxCNnB6OEdmOXBubExkL0RuV1NWM2dTKy9JL21BbDFkQ2tLYnk2SDJWNzkwZTZJSG1JSzJLWW0zam0rClUrK0ZJZEdwQmRzUVRTZG1pWC9yQXl1eE1ETTBhZE1rTkJ3VGZRbVpRQ3o2bkdIdzFRY1NQWk12WnBzQzhTa3YKZWt6eHNqRjFvdE9yTVVQTlBRdnRUV3JWeDhHbFIycWZ4LzR4YlFhMXYyZnJOdkZCQ21PNTlnb3oram5XdmZUdApqMk5qd0RaN3ZsTUJzUG0xNmRiS1lDODQwdXZSb1pqeHFzZGMzQ2hDWmpxaW1GcWxORy94b1BBOCtkVGljWnpDClhFOWlqUEljdlc2eTFhYTNiR3c9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K" | ||||
|         } | ||||
|       } | ||||
|     ] | ||||
|   }, | ||||
|   "ChallengeCerts": {} | ||||
| } | ||||
| @@ -1,536 +0,0 @@ | ||||
| package acme | ||||
|  | ||||
| import ( | ||||
| 	"crypto/tls" | ||||
| 	"encoding/base64" | ||||
| 	"net/http" | ||||
| 	"net/http/httptest" | ||||
| 	"reflect" | ||||
| 	"sync" | ||||
| 	"testing" | ||||
| 	"time" | ||||
|  | ||||
| 	acmeprovider "github.com/containous/traefik/provider/acme" | ||||
| 	"github.com/containous/traefik/tls/generate" | ||||
| 	"github.com/containous/traefik/types" | ||||
| 	"github.com/stretchr/testify/assert" | ||||
| 	"github.com/xenolf/lego/acmev2" | ||||
| ) | ||||
|  | ||||
| func TestDomainsSet(t *testing.T) { | ||||
| 	testCases := []struct { | ||||
| 		input    string | ||||
| 		expected types.Domains | ||||
| 	}{ | ||||
| 		{ | ||||
| 			input:    "", | ||||
| 			expected: types.Domains{}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			input: "foo1.com", | ||||
| 			expected: types.Domains{ | ||||
| 				types.Domain{Main: "foo1.com"}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			input: "foo2.com,bar.net", | ||||
| 			expected: types.Domains{ | ||||
| 				types.Domain{ | ||||
| 					Main: "foo2.com", | ||||
| 					SANs: []string{"bar.net"}, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			input: "foo3.com,bar1.net,bar2.net,bar3.net", | ||||
| 			expected: types.Domains{ | ||||
| 				types.Domain{ | ||||
| 					Main: "foo3.com", | ||||
| 					SANs: []string{"bar1.net", "bar2.net", "bar3.net"}, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range testCases { | ||||
| 		test := test | ||||
| 		t.Run(test.input, func(t *testing.T) { | ||||
| 			t.Parallel() | ||||
|  | ||||
| 			domains := types.Domains{} | ||||
| 			domains.Set(test.input) | ||||
| 			assert.Exactly(t, test.expected, domains) | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestDomainsSetAppend(t *testing.T) { | ||||
| 	testCases := []struct { | ||||
| 		input    string | ||||
| 		expected types.Domains | ||||
| 	}{ | ||||
| 		{ | ||||
| 			input:    "", | ||||
| 			expected: types.Domains{}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			input: "foo1.com", | ||||
| 			expected: types.Domains{ | ||||
| 				types.Domain{Main: "foo1.com"}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			input: "foo2.com,bar.net", | ||||
| 			expected: types.Domains{ | ||||
| 				types.Domain{Main: "foo1.com"}, | ||||
| 				types.Domain{ | ||||
| 					Main: "foo2.com", | ||||
| 					SANs: []string{"bar.net"}, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			input: "foo3.com,bar1.net,bar2.net,bar3.net", | ||||
| 			expected: types.Domains{ | ||||
| 				types.Domain{Main: "foo1.com"}, | ||||
| 				types.Domain{ | ||||
| 					Main: "foo2.com", | ||||
| 					SANs: []string{"bar.net"}, | ||||
| 				}, | ||||
| 				types.Domain{ | ||||
| 					Main: "foo3.com", | ||||
| 					SANs: []string{"bar1.net", "bar2.net", "bar3.net"}, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	// append to | ||||
| 	domains := types.Domains{} | ||||
| 	for _, test := range testCases { | ||||
| 		t.Run(test.input, func(t *testing.T) { | ||||
|  | ||||
| 			domains.Set(test.input) | ||||
| 			assert.Exactly(t, test.expected, domains) | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestCertificatesRenew(t *testing.T) { | ||||
| 	foo1Cert, foo1Key, _ := generate.KeyPair("foo1.com", time.Now()) | ||||
| 	foo2Cert, foo2Key, _ := generate.KeyPair("foo2.com", time.Now()) | ||||
|  | ||||
| 	domainsCertificates := DomainsCertificates{ | ||||
| 		lock: sync.RWMutex{}, | ||||
| 		Certs: []*DomainsCertificate{ | ||||
| 			{ | ||||
| 				Domains: types.Domain{ | ||||
| 					Main: "foo1.com"}, | ||||
| 				Certificate: &Certificate{ | ||||
| 					Domain:        "foo1.com", | ||||
| 					CertURL:       "url", | ||||
| 					CertStableURL: "url", | ||||
| 					PrivateKey:    foo1Key, | ||||
| 					Certificate:   foo1Cert, | ||||
| 				}, | ||||
| 			}, | ||||
| 			{ | ||||
| 				Domains: types.Domain{ | ||||
| 					Main: "foo2.com"}, | ||||
| 				Certificate: &Certificate{ | ||||
| 					Domain:        "foo2.com", | ||||
| 					CertURL:       "url", | ||||
| 					CertStableURL: "url", | ||||
| 					PrivateKey:    foo2Key, | ||||
| 					Certificate:   foo2Cert, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	foo1Cert, foo1Key, _ = generate.KeyPair("foo1.com", time.Now()) | ||||
| 	newCertificate := &Certificate{ | ||||
| 		Domain:        "foo1.com", | ||||
| 		CertURL:       "url", | ||||
| 		CertStableURL: "url", | ||||
| 		PrivateKey:    foo1Key, | ||||
| 		Certificate:   foo1Cert, | ||||
| 	} | ||||
|  | ||||
| 	err := domainsCertificates.renewCertificates(newCertificate, types.Domain{Main: "foo1.com"}) | ||||
| 	if err != nil { | ||||
| 		t.Errorf("Error in renewCertificates :%v", err) | ||||
| 	} | ||||
|  | ||||
| 	if len(domainsCertificates.Certs) != 2 { | ||||
| 		t.Errorf("Expected domainsCertificates length %d %+v\nGot %+v", 2, domainsCertificates.Certs, len(domainsCertificates.Certs)) | ||||
| 	} | ||||
|  | ||||
| 	if !reflect.DeepEqual(domainsCertificates.Certs[0].Certificate, newCertificate) { | ||||
| 		t.Errorf("Expected new certificate %+v \nGot %+v", newCertificate, domainsCertificates.Certs[0].Certificate) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestRemoveDuplicates(t *testing.T) { | ||||
| 	now := time.Now() | ||||
| 	fooCert, fooKey, _ := generate.KeyPair("foo.com", now) | ||||
| 	foo24Cert, foo24Key, _ := generate.KeyPair("foo.com", now.Add(24*time.Hour)) | ||||
| 	foo48Cert, foo48Key, _ := generate.KeyPair("foo.com", now.Add(48*time.Hour)) | ||||
| 	barCert, barKey, _ := generate.KeyPair("bar.com", now) | ||||
| 	domainsCertificates := DomainsCertificates{ | ||||
| 		lock: sync.RWMutex{}, | ||||
| 		Certs: []*DomainsCertificate{ | ||||
| 			{ | ||||
| 				Domains: types.Domain{ | ||||
| 					Main: "foo.com"}, | ||||
| 				Certificate: &Certificate{ | ||||
| 					Domain:        "foo.com", | ||||
| 					CertURL:       "url", | ||||
| 					CertStableURL: "url", | ||||
| 					PrivateKey:    foo24Key, | ||||
| 					Certificate:   foo24Cert, | ||||
| 				}, | ||||
| 			}, | ||||
| 			{ | ||||
| 				Domains: types.Domain{ | ||||
| 					Main: "foo.com"}, | ||||
| 				Certificate: &Certificate{ | ||||
| 					Domain:        "foo.com", | ||||
| 					CertURL:       "url", | ||||
| 					CertStableURL: "url", | ||||
| 					PrivateKey:    foo48Key, | ||||
| 					Certificate:   foo48Cert, | ||||
| 				}, | ||||
| 			}, | ||||
| 			{ | ||||
| 				Domains: types.Domain{ | ||||
| 					Main: "foo.com"}, | ||||
| 				Certificate: &Certificate{ | ||||
| 					Domain:        "foo.com", | ||||
| 					CertURL:       "url", | ||||
| 					CertStableURL: "url", | ||||
| 					PrivateKey:    fooKey, | ||||
| 					Certificate:   fooCert, | ||||
| 				}, | ||||
| 			}, | ||||
| 			{ | ||||
| 				Domains: types.Domain{ | ||||
| 					Main: "bar.com"}, | ||||
| 				Certificate: &Certificate{ | ||||
| 					Domain:        "bar.com", | ||||
| 					CertURL:       "url", | ||||
| 					CertStableURL: "url", | ||||
| 					PrivateKey:    barKey, | ||||
| 					Certificate:   barCert, | ||||
| 				}, | ||||
| 			}, | ||||
| 			{ | ||||
| 				Domains: types.Domain{ | ||||
| 					Main: "foo.com"}, | ||||
| 				Certificate: &Certificate{ | ||||
| 					Domain:        "foo.com", | ||||
| 					CertURL:       "url", | ||||
| 					CertStableURL: "url", | ||||
| 					PrivateKey:    foo48Key, | ||||
| 					Certificate:   foo48Cert, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 	} | ||||
| 	domainsCertificates.Init() | ||||
|  | ||||
| 	if len(domainsCertificates.Certs) != 2 { | ||||
| 		t.Errorf("Expected domainsCertificates length %d %+v\nGot %+v", 2, domainsCertificates.Certs, len(domainsCertificates.Certs)) | ||||
| 	} | ||||
|  | ||||
| 	for _, cert := range domainsCertificates.Certs { | ||||
| 		switch cert.Domains.Main { | ||||
| 		case "bar.com": | ||||
| 			continue | ||||
| 		case "foo.com": | ||||
| 			if !cert.tlsCert.Leaf.NotAfter.Equal(now.Add(48 * time.Hour).Truncate(1 * time.Second)) { | ||||
| 				t.Errorf("Bad expiration %s date for domain %+v, now %s", cert.tlsCert.Leaf.NotAfter.String(), cert, now.Add(48*time.Hour).Truncate(1*time.Second).String()) | ||||
| 			} | ||||
| 		default: | ||||
| 			t.Errorf("Unknown domain %+v", cert) | ||||
| 		} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestNoPreCheckOverride(t *testing.T) { | ||||
| 	acme.PreCheckDNS = nil // Irreversable - but not expecting real calls into this during testing process | ||||
| 	err := dnsOverrideDelay(0) | ||||
| 	if err != nil { | ||||
| 		t.Errorf("Error in dnsOverrideDelay :%v", err) | ||||
| 	} | ||||
| 	if acme.PreCheckDNS != nil { | ||||
| 		t.Error("Unexpected change to acme.PreCheckDNS when leaving DNS verification as is.") | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestSillyPreCheckOverride(t *testing.T) { | ||||
| 	err := dnsOverrideDelay(-5) | ||||
| 	if err == nil { | ||||
| 		t.Error("Missing expected error in dnsOverrideDelay!") | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestPreCheckOverride(t *testing.T) { | ||||
| 	acme.PreCheckDNS = nil // Irreversable - but not expecting real calls into this during testing process | ||||
| 	err := dnsOverrideDelay(5) | ||||
| 	if err != nil { | ||||
| 		t.Errorf("Error in dnsOverrideDelay :%v", err) | ||||
| 	} | ||||
| 	if acme.PreCheckDNS == nil { | ||||
| 		t.Error("No change to acme.PreCheckDNS when meant to be adding enforcing override function.") | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestAcmeClientCreation(t *testing.T) { | ||||
| 	acme.PreCheckDNS = nil // Irreversable - but not expecting real calls into this during testing process | ||||
| 	// Lengthy setup to avoid external web requests - oh for easier golang testing! | ||||
| 	account := &Account{Email: "f@f"} | ||||
| 	account.PrivateKey, _ = base64.StdEncoding.DecodeString(` | ||||
| MIIBPAIBAAJBAMp2Ni92FfEur+CAvFkgC12LT4l9D53ApbBpDaXaJkzzks+KsLw9zyAxvlrfAyTCQ | ||||
| 7tDnEnIltAXyQ0uOFUUdcMCAwEAAQJAK1FbipATZcT9cGVa5x7KD7usytftLW14heQUPXYNV80r/3 | ||||
| lmnpvjL06dffRpwkYeN8DATQF/QOcy3NNNGDw/4QIhAPAKmiZFxA/qmRXsuU8Zhlzf16WrNZ68K64 | ||||
| asn/h3qZrAiEA1+wFR3WXCPIolOvd7AHjfgcTKQNkoMPywU4FYUNQ1AkCIQDv8yk0qPjckD6HVCPJ | ||||
| llJh9MC0svjevGtNlxJoE3lmEQIhAKXy1wfZ32/XtcrnENPvi6lzxI0T94X7s5pP3aCoPPoJAiEAl | ||||
| cijFkALeQp/qyeXdFld2v9gUN3eCgljgcl0QweRoIc=---`) | ||||
| 	ts := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { | ||||
| 		w.Write([]byte(`{ | ||||
|   "GPHhmRVEDas": "https://community.letsencrypt.org/t/adding-random-entries-to-the-directory/33417", | ||||
|   "keyChange": "https://foo/acme/key-change", | ||||
|   "meta": { | ||||
|     "termsOfService": "https://boulder:4431/terms/v7" | ||||
|   }, | ||||
|   "newAccount": "https://foo/acme/new-acct", | ||||
|   "newNonce": "https://foo/acme/new-nonce", | ||||
|   "newOrder": "https://foo/acme/new-order", | ||||
|   "revokeCert": "https://foo/acme/revoke-cert" | ||||
| }`)) | ||||
| 	})) | ||||
| 	defer ts.Close() | ||||
| 	a := ACME{DNSChallenge: &acmeprovider.DNSChallenge{Provider: "manual", DelayBeforeCheck: 10}, CAServer: ts.URL} | ||||
|  | ||||
| 	client, err := a.buildACMEClient(account) | ||||
| 	if err != nil { | ||||
| 		t.Errorf("Error in buildACMEClient: %v", err) | ||||
| 	} | ||||
| 	if client == nil { | ||||
| 		t.Error("No client from buildACMEClient!") | ||||
| 	} | ||||
| 	if acme.PreCheckDNS == nil { | ||||
| 		t.Error("No change to acme.PreCheckDNS when meant to be adding enforcing override function.") | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestAcme_getUncheckedCertificates(t *testing.T) { | ||||
| 	mm := make(map[string]*tls.Certificate) | ||||
| 	mm["*.containo.us"] = &tls.Certificate{} | ||||
| 	mm["traefik.acme.io"] = &tls.Certificate{} | ||||
|  | ||||
| 	a := ACME{TLSConfig: &tls.Config{NameToCertificate: mm}} | ||||
|  | ||||
| 	domains := []string{"traefik.containo.us", "trae.containo.us"} | ||||
| 	uncheckedDomains := a.getUncheckedDomains(domains, nil) | ||||
| 	assert.Empty(t, uncheckedDomains) | ||||
| 	domains = []string{"traefik.acme.io", "trae.acme.io"} | ||||
| 	uncheckedDomains = a.getUncheckedDomains(domains, nil) | ||||
| 	assert.Len(t, uncheckedDomains, 1) | ||||
| 	domainsCertificates := DomainsCertificates{Certs: []*DomainsCertificate{ | ||||
| 		{ | ||||
| 			tlsCert: &tls.Certificate{}, | ||||
| 			Domains: types.Domain{ | ||||
| 				Main: "*.acme.wtf", | ||||
| 				SANs: []string{"trae.acme.io"}, | ||||
| 			}, | ||||
| 		}, | ||||
| 	}} | ||||
| 	account := Account{DomainsCertificate: domainsCertificates} | ||||
| 	uncheckedDomains = a.getUncheckedDomains(domains, &account) | ||||
| 	assert.Empty(t, uncheckedDomains) | ||||
| } | ||||
|  | ||||
| func TestAcme_getProvidedCertificate(t *testing.T) { | ||||
| 	mm := make(map[string]*tls.Certificate) | ||||
| 	mm["*.containo.us"] = &tls.Certificate{} | ||||
| 	mm["traefik.acme.io"] = &tls.Certificate{} | ||||
|  | ||||
| 	a := ACME{TLSConfig: &tls.Config{NameToCertificate: mm}} | ||||
|  | ||||
| 	domain := "traefik.containo.us" | ||||
| 	certificate := a.getProvidedCertificate(domain) | ||||
| 	assert.NotNil(t, certificate) | ||||
| 	domain = "trae.acme.io" | ||||
| 	certificate = a.getProvidedCertificate(domain) | ||||
| 	assert.Nil(t, certificate) | ||||
| } | ||||
|  | ||||
| func TestAcme_getValidDomain(t *testing.T) { | ||||
| 	testCases := []struct { | ||||
| 		desc            string | ||||
| 		domains         []string | ||||
| 		wildcardAllowed bool | ||||
| 		dnsChallenge    *acmeprovider.DNSChallenge | ||||
| 		expectedErr     string | ||||
| 		expectedDomains []string | ||||
| 	}{ | ||||
| 		{ | ||||
| 			desc:            "valid wildcard", | ||||
| 			domains:         []string{"*.traefik.wtf"}, | ||||
| 			dnsChallenge:    &acmeprovider.DNSChallenge{}, | ||||
| 			wildcardAllowed: true, | ||||
| 			expectedErr:     "", | ||||
| 			expectedDomains: []string{"*.traefik.wtf"}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:            "no wildcard", | ||||
| 			domains:         []string{"traefik.wtf", "foo.traefik.wtf"}, | ||||
| 			dnsChallenge:    &acmeprovider.DNSChallenge{}, | ||||
| 			expectedErr:     "", | ||||
| 			wildcardAllowed: true, | ||||
| 			expectedDomains: []string{"traefik.wtf", "foo.traefik.wtf"}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:            "unauthorized wildcard", | ||||
| 			domains:         []string{"*.traefik.wtf"}, | ||||
| 			dnsChallenge:    &acmeprovider.DNSChallenge{}, | ||||
| 			wildcardAllowed: false, | ||||
| 			expectedErr:     "unable to generate a wildcard certificate for domain \"*.traefik.wtf\" from a 'Host' rule", | ||||
| 			expectedDomains: nil, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:            "no domain", | ||||
| 			domains:         []string{}, | ||||
| 			dnsChallenge:    nil, | ||||
| 			wildcardAllowed: true, | ||||
| 			expectedErr:     "unable to generate a certificate when no domain is given", | ||||
| 			expectedDomains: nil, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:            "no DNSChallenge", | ||||
| 			domains:         []string{"*.traefik.wtf", "foo.traefik.wtf"}, | ||||
| 			dnsChallenge:    nil, | ||||
| 			wildcardAllowed: true, | ||||
| 			expectedErr:     "unable to generate a wildcard certificate for domain \"*.traefik.wtf,foo.traefik.wtf\" : ACME needs a DNSChallenge", | ||||
| 			expectedDomains: nil, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:            "unexpected SANs", | ||||
| 			domains:         []string{"*.traefik.wtf", "foo.traefik.wtf"}, | ||||
| 			dnsChallenge:    &acmeprovider.DNSChallenge{}, | ||||
| 			wildcardAllowed: true, | ||||
| 			expectedErr:     "unable to generate a wildcard certificate for domain \"*.traefik.wtf,foo.traefik.wtf\" : SANs are not allowed", | ||||
| 			expectedDomains: nil, | ||||
| 		}, | ||||
| 	} | ||||
| 	for _, test := range testCases { | ||||
| 		test := test | ||||
| 		t.Run(test.desc, func(t *testing.T) { | ||||
| 			t.Parallel() | ||||
|  | ||||
| 			a := ACME{} | ||||
| 			if test.dnsChallenge != nil { | ||||
| 				a.DNSChallenge = test.dnsChallenge | ||||
| 			} | ||||
| 			domains, err := a.getValidDomains(test.domains, test.wildcardAllowed) | ||||
|  | ||||
| 			if len(test.expectedErr) > 0 { | ||||
| 				assert.EqualError(t, err, test.expectedErr, "Unexpected error.") | ||||
| 			} else { | ||||
| 				assert.Equal(t, len(test.expectedDomains), len(domains), "Unexpected domains.") | ||||
| 			} | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestAcme_getCertificateForDomain(t *testing.T) { | ||||
| 	testCases := []struct { | ||||
| 		desc          string | ||||
| 		domain        string | ||||
| 		dc            *DomainsCertificates | ||||
| 		expected      *DomainsCertificate | ||||
| 		expectedFound bool | ||||
| 	}{ | ||||
| 		{ | ||||
| 			desc:   "non-wildcard exact match", | ||||
| 			domain: "foo.traefik.wtf", | ||||
| 			dc: &DomainsCertificates{ | ||||
| 				Certs: []*DomainsCertificate{ | ||||
| 					{ | ||||
| 						Domains: types.Domain{ | ||||
| 							Main: "foo.traefik.wtf", | ||||
| 						}, | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: &DomainsCertificate{ | ||||
| 				Domains: types.Domain{ | ||||
| 					Main: "foo.traefik.wtf", | ||||
| 				}, | ||||
| 			}, | ||||
| 			expectedFound: true, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:   "non-wildcard no match", | ||||
| 			domain: "bar.traefik.wtf", | ||||
| 			dc: &DomainsCertificates{ | ||||
| 				Certs: []*DomainsCertificate{ | ||||
| 					{ | ||||
| 						Domains: types.Domain{ | ||||
| 							Main: "foo.traefik.wtf", | ||||
| 						}, | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected:      nil, | ||||
| 			expectedFound: false, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:   "wildcard match", | ||||
| 			domain: "foo.traefik.wtf", | ||||
| 			dc: &DomainsCertificates{ | ||||
| 				Certs: []*DomainsCertificate{ | ||||
| 					{ | ||||
| 						Domains: types.Domain{ | ||||
| 							Main: "*.traefik.wtf", | ||||
| 						}, | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: &DomainsCertificate{ | ||||
| 				Domains: types.Domain{ | ||||
| 					Main: "*.traefik.wtf", | ||||
| 				}, | ||||
| 			}, | ||||
| 			expectedFound: true, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:   "wildcard no match", | ||||
| 			domain: "foo.traefik.wtf", | ||||
| 			dc: &DomainsCertificates{ | ||||
| 				Certs: []*DomainsCertificate{ | ||||
| 					{ | ||||
| 						Domains: types.Domain{ | ||||
| 							Main: "*.bar.traefik.wtf", | ||||
| 						}, | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected:      nil, | ||||
| 			expectedFound: false, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range testCases { | ||||
| 		test := test | ||||
| 		t.Run(test.desc, func(t *testing.T) { | ||||
| 			t.Parallel() | ||||
|  | ||||
| 			got, found := test.dc.getCertificateForDomain(test.domain) | ||||
| 			assert.Equal(t, test.expectedFound, found) | ||||
| 			assert.Equal(t, test.expected, got) | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
| @@ -1,92 +0,0 @@ | ||||
| package acme | ||||
|  | ||||
| import ( | ||||
| 	"fmt" | ||||
| 	"sync" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/cenk/backoff" | ||||
| 	"github.com/containous/traefik/cluster" | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/safe" | ||||
| 	acme "github.com/xenolf/lego/acmev2" | ||||
| ) | ||||
|  | ||||
| var _ acme.ChallengeProviderTimeout = (*challengeHTTPProvider)(nil) | ||||
|  | ||||
| type challengeHTTPProvider struct { | ||||
| 	store cluster.Store | ||||
| 	lock  sync.RWMutex | ||||
| } | ||||
|  | ||||
| func (c *challengeHTTPProvider) getTokenValue(token, domain string) []byte { | ||||
| 	log.Debugf("Looking for an existing ACME challenge for token %v...", token) | ||||
| 	c.lock.RLock() | ||||
| 	defer c.lock.RUnlock() | ||||
| 	account := c.store.Get().(*Account) | ||||
| 	if account.HTTPChallenge == nil { | ||||
| 		return []byte{} | ||||
| 	} | ||||
| 	var result []byte | ||||
| 	operation := func() error { | ||||
| 		var ok bool | ||||
| 		if result, ok = account.HTTPChallenge[token][domain]; !ok { | ||||
| 			return fmt.Errorf("cannot find challenge for token %v", token) | ||||
| 		} | ||||
| 		return nil | ||||
| 	} | ||||
| 	notify := func(err error, time time.Duration) { | ||||
| 		log.Errorf("Error getting challenge for token retrying in %s", time) | ||||
| 	} | ||||
| 	ebo := backoff.NewExponentialBackOff() | ||||
| 	ebo.MaxElapsedTime = 60 * time.Second | ||||
| 	err := backoff.RetryNotify(safe.OperationWithRecover(operation), ebo, notify) | ||||
| 	if err != nil { | ||||
| 		log.Errorf("Error getting challenge for token: %v", err) | ||||
| 		return []byte{} | ||||
| 	} | ||||
| 	return result | ||||
| } | ||||
|  | ||||
| func (c *challengeHTTPProvider) Present(domain, token, keyAuth string) error { | ||||
| 	log.Debugf("Challenge Present %s", domain) | ||||
| 	c.lock.Lock() | ||||
| 	defer c.lock.Unlock() | ||||
| 	transaction, object, err := c.store.Begin() | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	account := object.(*Account) | ||||
| 	if account.HTTPChallenge == nil { | ||||
| 		account.HTTPChallenge = map[string]map[string][]byte{} | ||||
| 	} | ||||
| 	if _, ok := account.HTTPChallenge[token]; !ok { | ||||
| 		account.HTTPChallenge[token] = map[string][]byte{} | ||||
| 	} | ||||
| 	account.HTTPChallenge[token][domain] = []byte(keyAuth) | ||||
| 	return transaction.Commit(account) | ||||
| } | ||||
|  | ||||
| func (c *challengeHTTPProvider) CleanUp(domain, token, keyAuth string) error { | ||||
| 	log.Debugf("Challenge CleanUp %s", domain) | ||||
| 	c.lock.Lock() | ||||
| 	defer c.lock.Unlock() | ||||
| 	transaction, object, err := c.store.Begin() | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	account := object.(*Account) | ||||
| 	if _, ok := account.HTTPChallenge[token]; ok { | ||||
| 		if _, domainOk := account.HTTPChallenge[token][domain]; domainOk { | ||||
| 			delete(account.HTTPChallenge[token], domain) | ||||
| 		} | ||||
| 		if len(account.HTTPChallenge[token]) == 0 { | ||||
| 			delete(account.HTTPChallenge, token) | ||||
| 		} | ||||
| 	} | ||||
| 	return transaction.Commit(account) | ||||
| } | ||||
|  | ||||
| func (c *challengeHTTPProvider) Timeout() (timeout, interval time.Duration) { | ||||
| 	return 60 * time.Second, 5 * time.Second | ||||
| } | ||||
| @@ -1,169 +0,0 @@ | ||||
| package acme | ||||
|  | ||||
| import ( | ||||
| 	"encoding/json" | ||||
| 	"io/ioutil" | ||||
| 	"os" | ||||
| 	"regexp" | ||||
|  | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/provider/acme" | ||||
| ) | ||||
|  | ||||
| // LocalStore is a store using a file as storage | ||||
| type LocalStore struct { | ||||
| 	file string | ||||
| } | ||||
|  | ||||
| // NewLocalStore create a LocalStore | ||||
| func NewLocalStore(file string) *LocalStore { | ||||
| 	return &LocalStore{ | ||||
| 		file: file, | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // Get loads file into store and returns the Account | ||||
| func (s *LocalStore) Get() (*Account, error) { | ||||
| 	account := &Account{} | ||||
|  | ||||
| 	hasData, err := checkFile(s.file) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	if hasData { | ||||
| 		f, err := os.Open(s.file) | ||||
| 		if err != nil { | ||||
| 			return nil, err | ||||
| 		} | ||||
| 		defer f.Close() | ||||
|  | ||||
| 		file, err := ioutil.ReadAll(f) | ||||
| 		if err != nil { | ||||
| 			return nil, err | ||||
| 		} | ||||
|  | ||||
| 		if err := json.Unmarshal(file, &account); err != nil { | ||||
| 			return nil, err | ||||
| 		} | ||||
|  | ||||
| 		// Check if ACME Account is in ACME V1 format | ||||
| 		if account != nil && account.Registration != nil { | ||||
| 			isOldRegistration, err := regexp.MatchString(acme.RegistrationURLPathV1Regexp, account.Registration.URI) | ||||
| 			if err != nil { | ||||
| 				return nil, err | ||||
| 			} | ||||
|  | ||||
| 			if isOldRegistration { | ||||
| 				account.Email = "" | ||||
| 				account.Registration = nil | ||||
| 				account.PrivateKey = nil | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return account, nil | ||||
| } | ||||
|  | ||||
| // ConvertToNewFormat converts old acme.json format to the new one and store the result into the file (used for the backward compatibility) | ||||
| func ConvertToNewFormat(fileName string) { | ||||
| 	localStore := acme.NewLocalStore(fileName) | ||||
|  | ||||
| 	storeAccount, err := localStore.GetAccount() | ||||
| 	if err != nil { | ||||
| 		log.Warnf("Failed to read new account, ACME data conversion is not available : %v", err) | ||||
| 		return | ||||
| 	} | ||||
|  | ||||
| 	storeCertificates, err := localStore.GetCertificates() | ||||
| 	if err != nil { | ||||
| 		log.Warnf("Failed to read new certificates, ACME data conversion is not available : %v", err) | ||||
| 		return | ||||
| 	} | ||||
|  | ||||
| 	if storeAccount == nil { | ||||
| 		localStore := NewLocalStore(fileName) | ||||
|  | ||||
| 		account, err := localStore.Get() | ||||
| 		if err != nil { | ||||
| 			log.Warnf("Failed to read old account, ACME data conversion is not available : %v", err) | ||||
| 			return | ||||
| 		} | ||||
|  | ||||
| 		// Convert ACME data from old to new format | ||||
| 		newAccount := &acme.Account{} | ||||
| 		if account != nil && len(account.Email) > 0 { | ||||
| 			newAccount = &acme.Account{ | ||||
| 				PrivateKey:   account.PrivateKey, | ||||
| 				Registration: account.Registration, | ||||
| 				Email:        account.Email, | ||||
| 			} | ||||
|  | ||||
| 			var newCertificates []*acme.Certificate | ||||
| 			for _, cert := range account.DomainsCertificate.Certs { | ||||
| 				newCertificates = append(newCertificates, &acme.Certificate{ | ||||
| 					Certificate: cert.Certificate.Certificate, | ||||
| 					Key:         cert.Certificate.PrivateKey, | ||||
| 					Domain:      cert.Domains, | ||||
| 				}) | ||||
| 			} | ||||
| 			// If account is in the old format, storeCertificates is nil or empty | ||||
| 			// and has to be initialized | ||||
| 			storeCertificates = newCertificates | ||||
| 		} | ||||
|  | ||||
| 		// Store the data in new format into the file even if account is nil | ||||
| 		// to delete Account in ACME v1 format and keeping the certificates | ||||
| 		newLocalStore := acme.NewLocalStore(fileName) | ||||
| 		newLocalStore.SaveDataChan <- &acme.StoredData{Account: newAccount, Certificates: storeCertificates} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // FromNewToOldFormat converts new acme.json format to the old one (used for the backward compatibility) | ||||
| func FromNewToOldFormat(fileName string) (*Account, error) { | ||||
| 	localStore := acme.NewLocalStore(fileName) | ||||
|  | ||||
| 	storeAccount, err := localStore.GetAccount() | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	storeCertificates, err := localStore.GetCertificates() | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	// Convert ACME Account from new to old format | ||||
| 	// (Needed by the KV stores) | ||||
| 	var account *Account | ||||
| 	if storeAccount != nil { | ||||
| 		account = &Account{ | ||||
| 			Email:              storeAccount.Email, | ||||
| 			PrivateKey:         storeAccount.PrivateKey, | ||||
| 			Registration:       storeAccount.Registration, | ||||
| 			DomainsCertificate: DomainsCertificates{}, | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	// Convert ACME Certificates from new to old format | ||||
| 	// (Needed by the KV stores) | ||||
| 	if len(storeCertificates) > 0 { | ||||
| 		// Account can be nil if data are migrated from new format | ||||
| 		// with a ACME V1 Account | ||||
| 		if account == nil { | ||||
| 			account = &Account{} | ||||
| 		} | ||||
| 		for _, cert := range storeCertificates { | ||||
| 			_, err := account.DomainsCertificate.addCertificateForDomains(&Certificate{ | ||||
| 				Domain:      cert.Domain.Main, | ||||
| 				Certificate: cert.Certificate, | ||||
| 				PrivateKey:  cert.Key, | ||||
| 			}, cert.Domain) | ||||
| 			if err != nil { | ||||
| 				return nil, err | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return account, nil | ||||
| } | ||||
| @@ -1,31 +0,0 @@ | ||||
| package acme | ||||
|  | ||||
| import ( | ||||
| 	"io/ioutil" | ||||
| 	"os" | ||||
| 	"path/filepath" | ||||
| 	"testing" | ||||
|  | ||||
| 	"github.com/stretchr/testify/assert" | ||||
| ) | ||||
|  | ||||
| func TestGet(t *testing.T) { | ||||
| 	acmeFile := "./acme_example.json" | ||||
|  | ||||
| 	folder, prefix := filepath.Split(acmeFile) | ||||
| 	tmpFile, err := ioutil.TempFile(folder, prefix) | ||||
| 	defer os.Remove(tmpFile.Name()) | ||||
|  | ||||
| 	assert.NoError(t, err) | ||||
|  | ||||
| 	fileContent, err := ioutil.ReadFile(acmeFile) | ||||
| 	assert.NoError(t, err) | ||||
|  | ||||
| 	tmpFile.Write(fileContent) | ||||
|  | ||||
| 	localStore := NewLocalStore(tmpFile.Name()) | ||||
| 	account, err := localStore.Get() | ||||
| 	assert.NoError(t, err) | ||||
|  | ||||
| 	assert.Len(t, account.DomainsCertificate.Certs, 1) | ||||
| } | ||||
| @@ -1,28 +0,0 @@ | ||||
| // +build !windows | ||||
|  | ||||
| package acme | ||||
|  | ||||
| import ( | ||||
| 	"fmt" | ||||
| 	"os" | ||||
| ) | ||||
|  | ||||
| // Check file permissions and content size | ||||
| func checkFile(name string) (bool, error) { | ||||
| 	f, err := os.Open(name) | ||||
| 	if err != nil { | ||||
| 		return false, err | ||||
| 	} | ||||
| 	defer f.Close() | ||||
|  | ||||
| 	fi, err := f.Stat() | ||||
| 	if err != nil { | ||||
| 		return false, err | ||||
| 	} | ||||
|  | ||||
| 	if fi.Mode().Perm()&0077 != 0 { | ||||
| 		return false, fmt.Errorf("permissions %o for %s are too open, please use 600", fi.Mode().Perm(), name) | ||||
| 	} | ||||
|  | ||||
| 	return fi.Size() > 0, nil | ||||
| } | ||||
| @@ -1,20 +0,0 @@ | ||||
| package acme | ||||
|  | ||||
| import "os" | ||||
|  | ||||
| // Check file content size | ||||
| // Do not check file permissions on Windows right now | ||||
| func checkFile(name string) (bool, error) { | ||||
| 	f, err := os.Open(name) | ||||
| 	if err != nil { | ||||
| 		return false, err | ||||
| 	} | ||||
| 	defer f.Close() | ||||
|  | ||||
| 	fi, err := f.Stat() | ||||
| 	if err != nil { | ||||
| 		return false, err | ||||
| 	} | ||||
|  | ||||
| 	return fi.Size() > 0, nil | ||||
| } | ||||
| @@ -1,136 +0,0 @@ | ||||
| package anonymize | ||||
|  | ||||
| import ( | ||||
| 	"encoding/json" | ||||
| 	"fmt" | ||||
| 	"reflect" | ||||
| 	"regexp" | ||||
|  | ||||
| 	"github.com/mitchellh/copystructure" | ||||
| 	"github.com/mvdan/xurls" | ||||
| ) | ||||
|  | ||||
| const ( | ||||
| 	maskShort = "xxxx" | ||||
| 	maskLarge = maskShort + maskShort + maskShort + maskShort + maskShort + maskShort + maskShort + maskShort | ||||
| ) | ||||
|  | ||||
| // Do configuration. | ||||
| func Do(baseConfig interface{}, indent bool) (string, error) { | ||||
| 	anomConfig, err := copystructure.Copy(baseConfig) | ||||
| 	if err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
|  | ||||
| 	val := reflect.ValueOf(anomConfig) | ||||
|  | ||||
| 	err = doOnStruct(val) | ||||
| 	if err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
|  | ||||
| 	configJSON, err := marshal(anomConfig, indent) | ||||
| 	if err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
|  | ||||
| 	return doOnJSON(string(configJSON)), nil | ||||
| } | ||||
|  | ||||
| func doOnJSON(input string) string { | ||||
| 	mailExp := regexp.MustCompile(`\w[-._\w]*\w@\w[-._\w]*\w\.\w{2,3}"`) | ||||
| 	return xurls.Relaxed.ReplaceAllString(mailExp.ReplaceAllString(input, maskLarge+"\""), maskLarge) | ||||
| } | ||||
|  | ||||
| func doOnStruct(field reflect.Value) error { | ||||
| 	switch field.Kind() { | ||||
| 	case reflect.Ptr: | ||||
| 		if !field.IsNil() { | ||||
| 			if err := doOnStruct(field.Elem()); err != nil { | ||||
| 				return err | ||||
| 			} | ||||
| 		} | ||||
| 	case reflect.Struct: | ||||
| 		for i := 0; i < field.NumField(); i++ { | ||||
| 			fld := field.Field(i) | ||||
| 			stField := field.Type().Field(i) | ||||
| 			if !isExported(stField) { | ||||
| 				continue | ||||
| 			} | ||||
| 			if stField.Tag.Get("export") == "true" { | ||||
| 				if err := doOnStruct(fld); err != nil { | ||||
| 					return err | ||||
| 				} | ||||
| 			} else { | ||||
| 				if err := reset(fld, stField.Name); err != nil { | ||||
| 					return err | ||||
| 				} | ||||
| 			} | ||||
| 		} | ||||
| 	case reflect.Map: | ||||
| 		for _, key := range field.MapKeys() { | ||||
| 			if err := doOnStruct(field.MapIndex(key)); err != nil { | ||||
| 				return err | ||||
| 			} | ||||
| 		} | ||||
| 	case reflect.Slice: | ||||
| 		for j := 0; j < field.Len(); j++ { | ||||
| 			if err := doOnStruct(field.Index(j)); err != nil { | ||||
| 				return err | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func reset(field reflect.Value, name string) error { | ||||
| 	if !field.CanSet() { | ||||
| 		return fmt.Errorf("cannot reset field %s", name) | ||||
| 	} | ||||
|  | ||||
| 	switch field.Kind() { | ||||
| 	case reflect.Ptr: | ||||
| 		if !field.IsNil() { | ||||
| 			field.Set(reflect.Zero(field.Type())) | ||||
| 		} | ||||
| 	case reflect.Struct: | ||||
| 		if field.IsValid() { | ||||
| 			field.Set(reflect.Zero(field.Type())) | ||||
| 		} | ||||
| 	case reflect.String: | ||||
| 		if field.String() != "" { | ||||
| 			field.Set(reflect.ValueOf(maskShort)) | ||||
| 		} | ||||
| 	case reflect.Map: | ||||
| 		if field.Len() > 0 { | ||||
| 			field.Set(reflect.MakeMap(field.Type())) | ||||
| 		} | ||||
| 	case reflect.Slice: | ||||
| 		if field.Len() > 0 { | ||||
| 			field.Set(reflect.MakeSlice(field.Type(), 0, 0)) | ||||
| 		} | ||||
| 	case reflect.Interface: | ||||
| 		if !field.IsNil() { | ||||
| 			return reset(field.Elem(), "") | ||||
| 		} | ||||
| 	default: | ||||
| 		// Primitive type | ||||
| 		field.Set(reflect.Zero(field.Type())) | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| // isExported return true is a struct field is exported, else false | ||||
| func isExported(f reflect.StructField) bool { | ||||
| 	if f.PkgPath != "" && !f.Anonymous { | ||||
| 		return false | ||||
| 	} | ||||
| 	return true | ||||
| } | ||||
|  | ||||
| func marshal(anomConfig interface{}, indent bool) ([]byte, error) { | ||||
| 	if indent { | ||||
| 		return json.MarshalIndent(anomConfig, "", " ") | ||||
| 	} | ||||
| 	return json.Marshal(anomConfig) | ||||
| } | ||||
| @@ -1,665 +0,0 @@ | ||||
| package anonymize | ||||
|  | ||||
| import ( | ||||
| 	"crypto/tls" | ||||
| 	"testing" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/containous/flaeg" | ||||
| 	"github.com/containous/traefik/acme" | ||||
| 	"github.com/containous/traefik/configuration" | ||||
| 	"github.com/containous/traefik/provider" | ||||
| 	acmeprovider "github.com/containous/traefik/provider/acme" | ||||
| 	"github.com/containous/traefik/provider/boltdb" | ||||
| 	"github.com/containous/traefik/provider/consul" | ||||
| 	"github.com/containous/traefik/provider/consulcatalog" | ||||
| 	"github.com/containous/traefik/provider/docker" | ||||
| 	"github.com/containous/traefik/provider/dynamodb" | ||||
| 	"github.com/containous/traefik/provider/ecs" | ||||
| 	"github.com/containous/traefik/provider/etcd" | ||||
| 	"github.com/containous/traefik/provider/eureka" | ||||
| 	"github.com/containous/traefik/provider/file" | ||||
| 	"github.com/containous/traefik/provider/kubernetes" | ||||
| 	"github.com/containous/traefik/provider/kv" | ||||
| 	"github.com/containous/traefik/provider/marathon" | ||||
| 	"github.com/containous/traefik/provider/mesos" | ||||
| 	"github.com/containous/traefik/provider/rancher" | ||||
| 	"github.com/containous/traefik/provider/zk" | ||||
| 	traefiktls "github.com/containous/traefik/tls" | ||||
| 	"github.com/containous/traefik/types" | ||||
| ) | ||||
|  | ||||
| func TestDo_globalConfiguration(t *testing.T) { | ||||
|  | ||||
| 	config := &configuration.GlobalConfiguration{} | ||||
|  | ||||
| 	config.GraceTimeOut = flaeg.Duration(666 * time.Second) | ||||
| 	config.Debug = true | ||||
| 	config.CheckNewVersion = true | ||||
| 	config.AccessLogsFile = "AccessLogsFile" | ||||
| 	config.AccessLog = &types.AccessLog{ | ||||
| 		FilePath: "AccessLog FilePath", | ||||
| 		Format:   "AccessLog Format", | ||||
| 	} | ||||
| 	config.TraefikLogsFile = "TraefikLogsFile" | ||||
| 	config.LogLevel = "LogLevel" | ||||
| 	config.EntryPoints = configuration.EntryPoints{ | ||||
| 		"foo": { | ||||
| 			Address: "foo Address", | ||||
| 			TLS: &traefiktls.TLS{ | ||||
| 				MinVersion:   "foo MinVersion", | ||||
| 				CipherSuites: []string{"foo CipherSuites 1", "foo CipherSuites 2", "foo CipherSuites 3"}, | ||||
| 				Certificates: traefiktls.Certificates{ | ||||
| 					{CertFile: "CertFile 1", KeyFile: "KeyFile 1"}, | ||||
| 					{CertFile: "CertFile 2", KeyFile: "KeyFile 2"}, | ||||
| 				}, | ||||
| 				ClientCA: traefiktls.ClientCA{ | ||||
| 					Files:    []string{"foo ClientCAFiles 1", "foo ClientCAFiles 2", "foo ClientCAFiles 3"}, | ||||
| 					Optional: false, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Redirect: &types.Redirect{ | ||||
| 				Replacement: "foo Replacement", | ||||
| 				Regex:       "foo Regex", | ||||
| 				EntryPoint:  "foo EntryPoint", | ||||
| 			}, | ||||
| 			Auth: &types.Auth{ | ||||
| 				Basic: &types.Basic{ | ||||
| 					UsersFile: "foo Basic UsersFile", | ||||
| 					Users:     types.Users{"foo Basic Users 1", "foo Basic Users 2", "foo Basic Users 3"}, | ||||
| 				}, | ||||
| 				Digest: &types.Digest{ | ||||
| 					UsersFile: "foo Digest UsersFile", | ||||
| 					Users:     types.Users{"foo Digest Users 1", "foo Digest Users 2", "foo Digest Users 3"}, | ||||
| 				}, | ||||
| 				Forward: &types.Forward{ | ||||
| 					Address: "foo Address", | ||||
| 					TLS: &types.ClientTLS{ | ||||
| 						CA:                 "foo CA", | ||||
| 						Cert:               "foo Cert", | ||||
| 						Key:                "foo Key", | ||||
| 						InsecureSkipVerify: true, | ||||
| 					}, | ||||
| 					TrustForwardHeader: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			WhitelistSourceRange: []string{"foo WhitelistSourceRange 1", "foo WhitelistSourceRange 2", "foo WhitelistSourceRange 3"}, | ||||
| 			Compress:             true, | ||||
| 			ProxyProtocol: &configuration.ProxyProtocol{ | ||||
| 				TrustedIPs: []string{"127.0.0.1/32", "192.168.0.1"}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		"fii": { | ||||
| 			Address: "fii Address", | ||||
| 			TLS: &traefiktls.TLS{ | ||||
| 				MinVersion:   "fii MinVersion", | ||||
| 				CipherSuites: []string{"fii CipherSuites 1", "fii CipherSuites 2", "fii CipherSuites 3"}, | ||||
| 				Certificates: traefiktls.Certificates{ | ||||
| 					{CertFile: "CertFile 1", KeyFile: "KeyFile 1"}, | ||||
| 					{CertFile: "CertFile 2", KeyFile: "KeyFile 2"}, | ||||
| 				}, | ||||
| 				ClientCA: traefiktls.ClientCA{ | ||||
| 					Files:    []string{"fii ClientCAFiles 1", "fii ClientCAFiles 2", "fii ClientCAFiles 3"}, | ||||
| 					Optional: false, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Redirect: &types.Redirect{ | ||||
| 				Replacement: "fii Replacement", | ||||
| 				Regex:       "fii Regex", | ||||
| 				EntryPoint:  "fii EntryPoint", | ||||
| 			}, | ||||
| 			Auth: &types.Auth{ | ||||
| 				Basic: &types.Basic{ | ||||
| 					UsersFile: "fii Basic UsersFile", | ||||
| 					Users:     types.Users{"fii Basic Users 1", "fii Basic Users 2", "fii Basic Users 3"}, | ||||
| 				}, | ||||
| 				Digest: &types.Digest{ | ||||
| 					UsersFile: "fii Digest UsersFile", | ||||
| 					Users:     types.Users{"fii Digest Users 1", "fii Digest Users 2", "fii Digest Users 3"}, | ||||
| 				}, | ||||
| 				Forward: &types.Forward{ | ||||
| 					Address: "fii Address", | ||||
| 					TLS: &types.ClientTLS{ | ||||
| 						CA:                 "fii CA", | ||||
| 						Cert:               "fii Cert", | ||||
| 						Key:                "fii Key", | ||||
| 						InsecureSkipVerify: true, | ||||
| 					}, | ||||
| 					TrustForwardHeader: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			WhitelistSourceRange: []string{"fii WhitelistSourceRange 1", "fii WhitelistSourceRange 2", "fii WhitelistSourceRange 3"}, | ||||
| 			Compress:             true, | ||||
| 			ProxyProtocol: &configuration.ProxyProtocol{ | ||||
| 				TrustedIPs: []string{"127.0.0.1/32", "192.168.0.1"}, | ||||
| 			}, | ||||
| 		}, | ||||
| 	} | ||||
| 	config.Cluster = &types.Cluster{ | ||||
| 		Node: "Cluster Node", | ||||
| 		Store: &types.Store{ | ||||
| 			Prefix: "Cluster Store Prefix", | ||||
| 			// ... | ||||
| 		}, | ||||
| 	} | ||||
| 	config.Constraints = types.Constraints{ | ||||
| 		{ | ||||
| 			Key:       "Constraints Key 1", | ||||
| 			Regex:     "Constraints Regex 2", | ||||
| 			MustMatch: true, | ||||
| 		}, | ||||
| 		{ | ||||
| 			Key:       "Constraints Key 1", | ||||
| 			Regex:     "Constraints Regex 2", | ||||
| 			MustMatch: true, | ||||
| 		}, | ||||
| 	} | ||||
| 	config.ACME = &acme.ACME{ | ||||
| 		Email: "acme Email", | ||||
| 		Domains: []types.Domain{ | ||||
| 			{ | ||||
| 				Main: "Domains Main", | ||||
| 				SANs: []string{"Domains acme SANs 1", "Domains acme SANs 2", "Domains acme SANs 3"}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		Storage:           "Storage", | ||||
| 		StorageFile:       "StorageFile", | ||||
| 		OnDemand:          true, | ||||
| 		OnHostRule:        true, | ||||
| 		CAServer:          "CAServer", | ||||
| 		EntryPoint:        "EntryPoint", | ||||
| 		DNSChallenge:      &acmeprovider.DNSChallenge{Provider: "DNSProvider"}, | ||||
| 		DelayDontCheckDNS: 666, | ||||
| 		ACMELogging:       true, | ||||
| 		TLSConfig: &tls.Config{ | ||||
| 			InsecureSkipVerify: true, | ||||
| 			// ... | ||||
| 		}, | ||||
| 	} | ||||
| 	config.DefaultEntryPoints = configuration.DefaultEntryPoints{"DefaultEntryPoints 1", "DefaultEntryPoints 2", "DefaultEntryPoints 3"} | ||||
| 	config.ProvidersThrottleDuration = flaeg.Duration(666 * time.Second) | ||||
| 	config.MaxIdleConnsPerHost = 666 | ||||
| 	config.IdleTimeout = flaeg.Duration(666 * time.Second) | ||||
| 	config.InsecureSkipVerify = true | ||||
| 	config.RootCAs = traefiktls.RootCAs{"RootCAs 1", "RootCAs 2", "RootCAs 3"} | ||||
| 	config.Retry = &configuration.Retry{ | ||||
| 		Attempts: 666, | ||||
| 	} | ||||
| 	config.HealthCheck = &configuration.HealthCheckConfig{ | ||||
| 		Interval: flaeg.Duration(666 * time.Second), | ||||
| 	} | ||||
| 	config.RespondingTimeouts = &configuration.RespondingTimeouts{ | ||||
| 		ReadTimeout:  flaeg.Duration(666 * time.Second), | ||||
| 		WriteTimeout: flaeg.Duration(666 * time.Second), | ||||
| 		IdleTimeout:  flaeg.Duration(666 * time.Second), | ||||
| 	} | ||||
| 	config.ForwardingTimeouts = &configuration.ForwardingTimeouts{ | ||||
| 		DialTimeout:           flaeg.Duration(666 * time.Second), | ||||
| 		ResponseHeaderTimeout: flaeg.Duration(666 * time.Second), | ||||
| 	} | ||||
| 	config.Docker = &docker.Provider{ | ||||
| 		BaseProvider: provider.BaseProvider{ | ||||
| 			Watch:    true, | ||||
| 			Filename: "docker Filename", | ||||
| 			Constraints: types.Constraints{ | ||||
| 				{ | ||||
| 					Key:       "docker Constraints Key 1", | ||||
| 					Regex:     "docker Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 				{ | ||||
| 					Key:       "docker Constraints Key 1", | ||||
| 					Regex:     "docker Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Trace: true, | ||||
| 			DebugLogGeneratedTemplate: true, | ||||
| 		}, | ||||
| 		Endpoint: "docker Endpoint", | ||||
| 		Domain:   "docker Domain", | ||||
| 		TLS: &types.ClientTLS{ | ||||
| 			CA:                 "docker CA", | ||||
| 			Cert:               "docker Cert", | ||||
| 			Key:                "docker Key", | ||||
| 			InsecureSkipVerify: true, | ||||
| 		}, | ||||
| 		ExposedByDefault: true, | ||||
| 		UseBindPortIP:    true, | ||||
| 		SwarmMode:        true, | ||||
| 	} | ||||
| 	config.File = &file.Provider{ | ||||
| 		BaseProvider: provider.BaseProvider{ | ||||
| 			Watch:    true, | ||||
| 			Filename: "file Filename", | ||||
| 			Constraints: types.Constraints{ | ||||
| 				{ | ||||
| 					Key:       "file Constraints Key 1", | ||||
| 					Regex:     "file Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 				{ | ||||
| 					Key:       "file Constraints Key 1", | ||||
| 					Regex:     "file Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Trace: true, | ||||
| 			DebugLogGeneratedTemplate: true, | ||||
| 		}, | ||||
| 		Directory: "file Directory", | ||||
| 	} | ||||
| 	config.Web = &configuration.WebCompatibility{ | ||||
| 		Address:  "web Address", | ||||
| 		CertFile: "web CertFile", | ||||
| 		KeyFile:  "web KeyFile", | ||||
| 		ReadOnly: true, | ||||
| 		Statistics: &types.Statistics{ | ||||
| 			RecentErrors: 666, | ||||
| 		}, | ||||
| 		Metrics: &types.Metrics{ | ||||
| 			Prometheus: &types.Prometheus{ | ||||
| 				Buckets: types.Buckets{6.5, 6.6, 6.7}, | ||||
| 			}, | ||||
| 			Datadog: &types.Datadog{ | ||||
| 				Address:      "Datadog Address", | ||||
| 				PushInterval: "Datadog PushInterval", | ||||
| 			}, | ||||
| 			StatsD: &types.Statsd{ | ||||
| 				Address:      "StatsD Address", | ||||
| 				PushInterval: "StatsD PushInterval", | ||||
| 			}, | ||||
| 		}, | ||||
| 		Path: "web Path", | ||||
| 		Auth: &types.Auth{ | ||||
| 			Basic: &types.Basic{ | ||||
| 				UsersFile: "web Basic UsersFile", | ||||
| 				Users:     types.Users{"web Basic Users 1", "web Basic Users 2", "web Basic Users 3"}, | ||||
| 			}, | ||||
| 			Digest: &types.Digest{ | ||||
| 				UsersFile: "web Digest UsersFile", | ||||
| 				Users:     types.Users{"web Digest Users 1", "web Digest Users 2", "web Digest Users 3"}, | ||||
| 			}, | ||||
| 			Forward: &types.Forward{ | ||||
| 				Address: "web Address", | ||||
| 				TLS: &types.ClientTLS{ | ||||
| 					CA:                 "web CA", | ||||
| 					Cert:               "web Cert", | ||||
| 					Key:                "web Key", | ||||
| 					InsecureSkipVerify: true, | ||||
| 				}, | ||||
| 				TrustForwardHeader: true, | ||||
| 			}, | ||||
| 		}, | ||||
| 		Debug: true, | ||||
| 	} | ||||
| 	config.Marathon = &marathon.Provider{ | ||||
| 		BaseProvider: provider.BaseProvider{ | ||||
| 			Watch:    true, | ||||
| 			Filename: "marathon Filename", | ||||
| 			Constraints: types.Constraints{ | ||||
| 				{ | ||||
| 					Key:       "marathon Constraints Key 1", | ||||
| 					Regex:     "marathon Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 				{ | ||||
| 					Key:       "marathon Constraints Key 1", | ||||
| 					Regex:     "marathon Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Trace: true, | ||||
| 			DebugLogGeneratedTemplate: true, | ||||
| 		}, | ||||
| 		Endpoint:                "", | ||||
| 		Domain:                  "", | ||||
| 		ExposedByDefault:        true, | ||||
| 		GroupsAsSubDomains:      true, | ||||
| 		DCOSToken:               "", | ||||
| 		MarathonLBCompatibility: true, | ||||
| 		TLS: &types.ClientTLS{ | ||||
| 			CA:                 "marathon CA", | ||||
| 			Cert:               "marathon Cert", | ||||
| 			Key:                "marathon Key", | ||||
| 			InsecureSkipVerify: true, | ||||
| 		}, | ||||
| 		DialerTimeout:     flaeg.Duration(666 * time.Second), | ||||
| 		KeepAlive:         flaeg.Duration(666 * time.Second), | ||||
| 		ForceTaskHostname: true, | ||||
| 		Basic: &marathon.Basic{ | ||||
| 			HTTPBasicAuthUser: "marathon HTTPBasicAuthUser", | ||||
| 			HTTPBasicPassword: "marathon HTTPBasicPassword", | ||||
| 		}, | ||||
| 		RespectReadinessChecks: true, | ||||
| 	} | ||||
| 	config.ConsulCatalog = &consulcatalog.Provider{ | ||||
| 		BaseProvider: provider.BaseProvider{ | ||||
| 			Watch:    true, | ||||
| 			Filename: "ConsulCatalog Filename", | ||||
| 			Constraints: types.Constraints{ | ||||
| 				{ | ||||
| 					Key:       "ConsulCatalog Constraints Key 1", | ||||
| 					Regex:     "ConsulCatalog Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 				{ | ||||
| 					Key:       "ConsulCatalog Constraints Key 1", | ||||
| 					Regex:     "ConsulCatalog Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Trace: true, | ||||
| 			DebugLogGeneratedTemplate: true, | ||||
| 		}, | ||||
| 		Endpoint:         "ConsulCatalog Endpoint", | ||||
| 		Domain:           "ConsulCatalog Domain", | ||||
| 		ExposedByDefault: true, | ||||
| 		Prefix:           "ConsulCatalog Prefix", | ||||
| 		FrontEndRule:     "ConsulCatalog FrontEndRule", | ||||
| 	} | ||||
| 	config.Kubernetes = &kubernetes.Provider{ | ||||
| 		BaseProvider: provider.BaseProvider{ | ||||
| 			Watch:    true, | ||||
| 			Filename: "k8s Filename", | ||||
| 			Constraints: types.Constraints{ | ||||
| 				{ | ||||
| 					Key:       "k8s Constraints Key 1", | ||||
| 					Regex:     "k8s Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 				{ | ||||
| 					Key:       "k8s Constraints Key 1", | ||||
| 					Regex:     "k8s Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Trace: true, | ||||
| 			DebugLogGeneratedTemplate: true, | ||||
| 		}, | ||||
| 		Endpoint:               "k8s Endpoint", | ||||
| 		Token:                  "k8s Token", | ||||
| 		CertAuthFilePath:       "k8s CertAuthFilePath", | ||||
| 		DisablePassHostHeaders: true, | ||||
| 		Namespaces:             kubernetes.Namespaces{"k8s Namespaces 1", "k8s Namespaces 2", "k8s Namespaces 3"}, | ||||
| 		LabelSelector:          "k8s LabelSelector", | ||||
| 	} | ||||
| 	config.Mesos = &mesos.Provider{ | ||||
| 		BaseProvider: provider.BaseProvider{ | ||||
| 			Watch:    true, | ||||
| 			Filename: "mesos Filename", | ||||
| 			Constraints: types.Constraints{ | ||||
| 				{ | ||||
| 					Key:       "mesos Constraints Key 1", | ||||
| 					Regex:     "mesos Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 				{ | ||||
| 					Key:       "mesos Constraints Key 1", | ||||
| 					Regex:     "mesos Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Trace: true, | ||||
| 			DebugLogGeneratedTemplate: true, | ||||
| 		}, | ||||
| 		Endpoint:           "mesos Endpoint", | ||||
| 		Domain:             "mesos Domain", | ||||
| 		ExposedByDefault:   true, | ||||
| 		GroupsAsSubDomains: true, | ||||
| 		ZkDetectionTimeout: 666, | ||||
| 		RefreshSeconds:     666, | ||||
| 		IPSources:          "mesos IPSources", | ||||
| 		StateTimeoutSecond: 666, | ||||
| 		Masters:            []string{"mesos Masters 1", "mesos Masters 2", "mesos Masters 3"}, | ||||
| 	} | ||||
| 	config.Eureka = &eureka.Provider{ | ||||
| 		BaseProvider: provider.BaseProvider{ | ||||
| 			Watch:    true, | ||||
| 			Filename: "eureka Filename", | ||||
| 			Constraints: types.Constraints{ | ||||
| 				{ | ||||
| 					Key:       "eureka Constraints Key 1", | ||||
| 					Regex:     "eureka Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 				{ | ||||
| 					Key:       "eureka Constraints Key 1", | ||||
| 					Regex:     "eureka Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Trace: true, | ||||
| 			DebugLogGeneratedTemplate: true, | ||||
| 		}, | ||||
| 		Endpoint:       "eureka Endpoint", | ||||
| 		Delay:          flaeg.Duration(30 * time.Second), | ||||
| 		RefreshSeconds: flaeg.Duration(30 * time.Second), | ||||
| 	} | ||||
| 	config.ECS = &ecs.Provider{ | ||||
| 		BaseProvider: provider.BaseProvider{ | ||||
| 			Watch:    true, | ||||
| 			Filename: "ecs Filename", | ||||
| 			Constraints: types.Constraints{ | ||||
| 				{ | ||||
| 					Key:       "ecs Constraints Key 1", | ||||
| 					Regex:     "ecs Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 				{ | ||||
| 					Key:       "ecs Constraints Key 1", | ||||
| 					Regex:     "ecs Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Trace: true, | ||||
| 			DebugLogGeneratedTemplate: true, | ||||
| 		}, | ||||
| 		Domain:               "ecs Domain", | ||||
| 		ExposedByDefault:     true, | ||||
| 		RefreshSeconds:       666, | ||||
| 		Clusters:             ecs.Clusters{"ecs Clusters 1", "ecs Clusters 2", "ecs Clusters 3"}, | ||||
| 		Cluster:              "ecs Cluster", | ||||
| 		AutoDiscoverClusters: true, | ||||
| 		Region:               "ecs Region", | ||||
| 		AccessKeyID:          "ecs AccessKeyID", | ||||
| 		SecretAccessKey:      "ecs SecretAccessKey", | ||||
| 	} | ||||
| 	config.Rancher = &rancher.Provider{ | ||||
| 		BaseProvider: provider.BaseProvider{ | ||||
| 			Watch:    true, | ||||
| 			Filename: "rancher Filename", | ||||
| 			Constraints: types.Constraints{ | ||||
| 				{ | ||||
| 					Key:       "rancher Constraints Key 1", | ||||
| 					Regex:     "rancher Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 				{ | ||||
| 					Key:       "rancher Constraints Key 1", | ||||
| 					Regex:     "rancher Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Trace: true, | ||||
| 			DebugLogGeneratedTemplate: true, | ||||
| 		}, | ||||
| 		APIConfiguration: rancher.APIConfiguration{ | ||||
| 			Endpoint:  "rancher Endpoint", | ||||
| 			AccessKey: "rancher AccessKey", | ||||
| 			SecretKey: "rancher SecretKey", | ||||
| 		}, | ||||
| 		API: &rancher.APIConfiguration{ | ||||
| 			Endpoint:  "rancher Endpoint", | ||||
| 			AccessKey: "rancher AccessKey", | ||||
| 			SecretKey: "rancher SecretKey", | ||||
| 		}, | ||||
| 		Metadata: &rancher.MetadataConfiguration{ | ||||
| 			IntervalPoll: true, | ||||
| 			Prefix:       "rancher Metadata Prefix", | ||||
| 		}, | ||||
| 		Domain:                    "rancher Domain", | ||||
| 		RefreshSeconds:            666, | ||||
| 		ExposedByDefault:          true, | ||||
| 		EnableServiceHealthFilter: true, | ||||
| 	} | ||||
| 	config.DynamoDB = &dynamodb.Provider{ | ||||
| 		BaseProvider: provider.BaseProvider{ | ||||
| 			Watch:    true, | ||||
| 			Filename: "dynamodb Filename", | ||||
| 			Constraints: types.Constraints{ | ||||
| 				{ | ||||
| 					Key:       "dynamodb Constraints Key 1", | ||||
| 					Regex:     "dynamodb Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 				{ | ||||
| 					Key:       "dynamodb Constraints Key 1", | ||||
| 					Regex:     "dynamodb Constraints Regex 2", | ||||
| 					MustMatch: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			Trace: true, | ||||
| 			DebugLogGeneratedTemplate: true, | ||||
| 		}, | ||||
| 		AccessKeyID:     "dynamodb AccessKeyID", | ||||
| 		RefreshSeconds:  666, | ||||
| 		Region:          "dynamodb Region", | ||||
| 		SecretAccessKey: "dynamodb SecretAccessKey", | ||||
| 		TableName:       "dynamodb TableName", | ||||
| 		Endpoint:        "dynamodb Endpoint", | ||||
| 	} | ||||
| 	config.Etcd = &etcd.Provider{ | ||||
| 		Provider: kv.Provider{ | ||||
| 			BaseProvider: provider.BaseProvider{ | ||||
| 				Watch:    true, | ||||
| 				Filename: "etcd Filename", | ||||
| 				Constraints: types.Constraints{ | ||||
| 					{ | ||||
| 						Key:       "etcd Constraints Key 1", | ||||
| 						Regex:     "etcd Constraints Regex 2", | ||||
| 						MustMatch: true, | ||||
| 					}, | ||||
| 					{ | ||||
| 						Key:       "etcd Constraints Key 1", | ||||
| 						Regex:     "etcd Constraints Regex 2", | ||||
| 						MustMatch: true, | ||||
| 					}, | ||||
| 				}, | ||||
| 				Trace: true, | ||||
| 				DebugLogGeneratedTemplate: true, | ||||
| 			}, | ||||
| 			Endpoint: "etcd Endpoint", | ||||
| 			Prefix:   "etcd Prefix", | ||||
| 			TLS: &types.ClientTLS{ | ||||
| 				CA:                 "etcd CA", | ||||
| 				Cert:               "etcd Cert", | ||||
| 				Key:                "etcd Key", | ||||
| 				InsecureSkipVerify: true, | ||||
| 			}, | ||||
| 			Username: "etcd Username", | ||||
| 			Password: "etcd Password", | ||||
| 		}, | ||||
| 	} | ||||
| 	config.Zookeeper = &zk.Provider{ | ||||
| 		Provider: kv.Provider{ | ||||
| 			BaseProvider: provider.BaseProvider{ | ||||
| 				Watch:    true, | ||||
| 				Filename: "zk Filename", | ||||
| 				Constraints: types.Constraints{ | ||||
| 					{ | ||||
| 						Key:       "zk Constraints Key 1", | ||||
| 						Regex:     "zk Constraints Regex 2", | ||||
| 						MustMatch: true, | ||||
| 					}, | ||||
| 					{ | ||||
| 						Key:       "zk Constraints Key 1", | ||||
| 						Regex:     "zk Constraints Regex 2", | ||||
| 						MustMatch: true, | ||||
| 					}, | ||||
| 				}, | ||||
| 				Trace: true, | ||||
| 				DebugLogGeneratedTemplate: true, | ||||
| 			}, | ||||
| 			Endpoint: "zk Endpoint", | ||||
| 			Prefix:   "zk Prefix", | ||||
| 			TLS: &types.ClientTLS{ | ||||
| 				CA:                 "zk CA", | ||||
| 				Cert:               "zk Cert", | ||||
| 				Key:                "zk Key", | ||||
| 				InsecureSkipVerify: true, | ||||
| 			}, | ||||
| 			Username: "zk Username", | ||||
| 			Password: "zk Password", | ||||
| 		}, | ||||
| 	} | ||||
| 	config.Boltdb = &boltdb.Provider{ | ||||
| 		Provider: kv.Provider{ | ||||
| 			BaseProvider: provider.BaseProvider{ | ||||
| 				Watch:    true, | ||||
| 				Filename: "boltdb Filename", | ||||
| 				Constraints: types.Constraints{ | ||||
| 					{ | ||||
| 						Key:       "boltdb Constraints Key 1", | ||||
| 						Regex:     "boltdb Constraints Regex 2", | ||||
| 						MustMatch: true, | ||||
| 					}, | ||||
| 					{ | ||||
| 						Key:       "boltdb Constraints Key 1", | ||||
| 						Regex:     "boltdb Constraints Regex 2", | ||||
| 						MustMatch: true, | ||||
| 					}, | ||||
| 				}, | ||||
| 				Trace: true, | ||||
| 				DebugLogGeneratedTemplate: true, | ||||
| 			}, | ||||
| 			Endpoint: "boltdb Endpoint", | ||||
| 			Prefix:   "boltdb Prefix", | ||||
| 			TLS: &types.ClientTLS{ | ||||
| 				CA:                 "boltdb CA", | ||||
| 				Cert:               "boltdb Cert", | ||||
| 				Key:                "boltdb Key", | ||||
| 				InsecureSkipVerify: true, | ||||
| 			}, | ||||
| 			Username: "boltdb Username", | ||||
| 			Password: "boltdb Password", | ||||
| 		}, | ||||
| 	} | ||||
| 	config.Consul = &consul.Provider{ | ||||
| 		Provider: kv.Provider{ | ||||
| 			BaseProvider: provider.BaseProvider{ | ||||
| 				Watch:    true, | ||||
| 				Filename: "consul Filename", | ||||
| 				Constraints: types.Constraints{ | ||||
| 					{ | ||||
| 						Key:       "consul Constraints Key 1", | ||||
| 						Regex:     "consul Constraints Regex 2", | ||||
| 						MustMatch: true, | ||||
| 					}, | ||||
| 					{ | ||||
| 						Key:       "consul Constraints Key 1", | ||||
| 						Regex:     "consul Constraints Regex 2", | ||||
| 						MustMatch: true, | ||||
| 					}, | ||||
| 				}, | ||||
| 				Trace: true, | ||||
| 				DebugLogGeneratedTemplate: true, | ||||
| 			}, | ||||
| 			Endpoint: "consul Endpoint", | ||||
| 			Prefix:   "consul Prefix", | ||||
| 			TLS: &types.ClientTLS{ | ||||
| 				CA:                 "consul CA", | ||||
| 				Cert:               "consul Cert", | ||||
| 				Key:                "consul Key", | ||||
| 				InsecureSkipVerify: true, | ||||
| 			}, | ||||
| 			Username: "consul Username", | ||||
| 			Password: "consul Password", | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	cleanJSON, err := Do(config, true) | ||||
| 	if err != nil { | ||||
| 		t.Fatal(err, cleanJSON) | ||||
| 	} | ||||
| } | ||||
| @@ -1,237 +0,0 @@ | ||||
| package anonymize | ||||
|  | ||||
| import ( | ||||
| 	"testing" | ||||
|  | ||||
| 	"github.com/stretchr/testify/assert" | ||||
| ) | ||||
|  | ||||
| func Test_doOnJSON(t *testing.T) { | ||||
| 	baseConfiguration := ` | ||||
| { | ||||
|  "GraceTimeOut": 10000000000, | ||||
|  "Debug": false, | ||||
|  "CheckNewVersion": true, | ||||
|  "AccessLogsFile": "", | ||||
|  "TraefikLogsFile": "", | ||||
|  "LogLevel": "ERROR", | ||||
|  "EntryPoints": { | ||||
|   "http": { | ||||
|    "Network": "", | ||||
|    "Address": ":80", | ||||
|    "TLS": null, | ||||
|    "Redirect": { | ||||
|     "EntryPoint": "https", | ||||
|     "Regex": "", | ||||
|     "Replacement": "" | ||||
|    }, | ||||
|    "Auth": null, | ||||
|    "Compress": false | ||||
|   }, | ||||
|   "https": { | ||||
|    "Address": ":443", | ||||
|    "TLS": { | ||||
|     "MinVersion": "", | ||||
|     "CipherSuites": null, | ||||
|     "Certificates": null, | ||||
|     "ClientCAFiles": null | ||||
|    }, | ||||
|    "Redirect": null, | ||||
|    "Auth": null, | ||||
|    "Compress": false | ||||
|   } | ||||
|  }, | ||||
|  "Cluster": null, | ||||
|  "Constraints": [], | ||||
|  "ACME": { | ||||
|   "Email": "foo@bar.com", | ||||
|   "Domains": [ | ||||
|    { | ||||
|     "Main": "foo@bar.com", | ||||
|     "SANs": null | ||||
|    }, | ||||
|    { | ||||
|     "Main": "foo@bar.com", | ||||
|     "SANs": null | ||||
|    } | ||||
|   ], | ||||
|   "Storage": "", | ||||
|   "StorageFile": "/acme/acme.json", | ||||
|   "OnDemand": true, | ||||
|   "OnHostRule": true, | ||||
|   "CAServer": "", | ||||
|   "EntryPoint": "https", | ||||
|   "DNSProvider": "", | ||||
|   "DelayDontCheckDNS": 0, | ||||
|   "ACMELogging": false, | ||||
|   "TLSConfig": null | ||||
|  }, | ||||
|  "DefaultEntryPoints": [ | ||||
|   "https", | ||||
|   "http" | ||||
|  ], | ||||
|  "ProvidersThrottleDuration": 2000000000, | ||||
|  "MaxIdleConnsPerHost": 200, | ||||
|  "IdleTimeout": 180000000000, | ||||
|  "InsecureSkipVerify": false, | ||||
|  "Retry": null, | ||||
|  "HealthCheck": { | ||||
|   "Interval": 30000000000 | ||||
|  }, | ||||
|  "Docker": null, | ||||
|  "File": null, | ||||
|  "Web": null, | ||||
|  "Marathon": null, | ||||
|  "Consul": null, | ||||
|  "ConsulCatalog": null, | ||||
|  "Etcd": null, | ||||
|  "Zookeeper": null, | ||||
|  "Boltdb": null, | ||||
|  "Kubernetes": null, | ||||
|  "Mesos": null, | ||||
|  "Eureka": null, | ||||
|  "ECS": null, | ||||
|  "Rancher": null, | ||||
|  "DynamoDB": null, | ||||
|  "ConfigFile": "/etc/traefik/traefik.toml" | ||||
| } | ||||
| ` | ||||
| 	expectedConfiguration := ` | ||||
| { | ||||
|  "GraceTimeOut": 10000000000, | ||||
|  "Debug": false, | ||||
|  "CheckNewVersion": true, | ||||
|  "AccessLogsFile": "", | ||||
|  "TraefikLogsFile": "", | ||||
|  "LogLevel": "ERROR", | ||||
|  "EntryPoints": { | ||||
|   "http": { | ||||
|    "Network": "", | ||||
|    "Address": ":80", | ||||
|    "TLS": null, | ||||
|    "Redirect": { | ||||
|     "EntryPoint": "https", | ||||
|     "Regex": "", | ||||
|     "Replacement": "" | ||||
|    }, | ||||
|    "Auth": null, | ||||
|    "Compress": false | ||||
|   }, | ||||
|   "https": { | ||||
|    "Address": ":443", | ||||
|    "TLS": { | ||||
|     "MinVersion": "", | ||||
|     "CipherSuites": null, | ||||
|     "Certificates": null, | ||||
|     "ClientCAFiles": null | ||||
|    }, | ||||
|    "Redirect": null, | ||||
|    "Auth": null, | ||||
|    "Compress": false | ||||
|   } | ||||
|  }, | ||||
|  "Cluster": null, | ||||
|  "Constraints": [], | ||||
|  "ACME": { | ||||
|   "Email": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx", | ||||
|   "Domains": [ | ||||
|    { | ||||
|     "Main": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx", | ||||
|     "SANs": null | ||||
|    }, | ||||
|    { | ||||
|     "Main": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx", | ||||
|     "SANs": null | ||||
|    } | ||||
|   ], | ||||
|   "Storage": "", | ||||
|   "StorageFile": "/acme/acme.json", | ||||
|   "OnDemand": true, | ||||
|   "OnHostRule": true, | ||||
|   "CAServer": "", | ||||
|   "EntryPoint": "https", | ||||
|   "DNSProvider": "", | ||||
|   "DelayDontCheckDNS": 0, | ||||
|   "ACMELogging": false, | ||||
|   "TLSConfig": null | ||||
|  }, | ||||
|  "DefaultEntryPoints": [ | ||||
|   "https", | ||||
|   "http" | ||||
|  ], | ||||
|  "ProvidersThrottleDuration": 2000000000, | ||||
|  "MaxIdleConnsPerHost": 200, | ||||
|  "IdleTimeout": 180000000000, | ||||
|  "InsecureSkipVerify": false, | ||||
|  "Retry": null, | ||||
|  "HealthCheck": { | ||||
|   "Interval": 30000000000 | ||||
|  }, | ||||
|  "Docker": null, | ||||
|  "File": null, | ||||
|  "Web": null, | ||||
|  "Marathon": null, | ||||
|  "Consul": null, | ||||
|  "ConsulCatalog": null, | ||||
|  "Etcd": null, | ||||
|  "Zookeeper": null, | ||||
|  "Boltdb": null, | ||||
|  "Kubernetes": null, | ||||
|  "Mesos": null, | ||||
|  "Eureka": null, | ||||
|  "ECS": null, | ||||
|  "Rancher": null, | ||||
|  "DynamoDB": null, | ||||
|  "ConfigFile": "/etc/traefik/traefik.toml" | ||||
| } | ||||
| ` | ||||
| 	anomConfiguration := doOnJSON(baseConfiguration) | ||||
|  | ||||
| 	if anomConfiguration != expectedConfiguration { | ||||
| 		t.Errorf("Got %s, want %s.", anomConfiguration, expectedConfiguration) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func Test_doOnJSON_simple(t *testing.T) { | ||||
| 	testCases := []struct { | ||||
| 		name           string | ||||
| 		input          string | ||||
| 		expectedOutput string | ||||
| 	}{ | ||||
| 		{ | ||||
| 			name: "email", | ||||
| 			input: `{ | ||||
| 				"email1": "goo@example.com", | ||||
| 				"email2": "foo.bargoo@example.com", | ||||
| 				"email3": "foo.bargoo@example.com.us" | ||||
| 			}`, | ||||
| 			expectedOutput: `{ | ||||
| 				"email1": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx", | ||||
| 				"email2": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx", | ||||
| 				"email3": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" | ||||
| 			}`, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name: "url", | ||||
| 			input: `{ | ||||
| 				"URL": "foo domain.com foo", | ||||
| 				"URL": "foo sub.domain.com foo", | ||||
| 				"URL": "foo sub.sub.domain.com foo", | ||||
| 				"URL": "foo sub.sub.sub.domain.com.us foo" | ||||
| 			}`, | ||||
| 			expectedOutput: `{ | ||||
| 				"URL": "foo xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx foo", | ||||
| 				"URL": "foo xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx foo", | ||||
| 				"URL": "foo xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx foo", | ||||
| 				"URL": "foo xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx foo" | ||||
| 			}`, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range testCases { | ||||
| 		t.Run(test.name, func(t *testing.T) { | ||||
| 			output := doOnJSON(test.input) | ||||
| 			assert.Equal(t, test.expectedOutput, output) | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
| @@ -1,176 +0,0 @@ | ||||
| package anonymize | ||||
|  | ||||
| import ( | ||||
| 	"reflect" | ||||
| 	"testing" | ||||
|  | ||||
| 	"github.com/stretchr/testify/assert" | ||||
| ) | ||||
|  | ||||
| type Courgette struct { | ||||
| 	Ji string | ||||
| 	Ho string | ||||
| } | ||||
| type Tomate struct { | ||||
| 	Ji string | ||||
| 	Ho string | ||||
| } | ||||
|  | ||||
| type Carotte struct { | ||||
| 	Name        string | ||||
| 	Value       int | ||||
| 	Courgette   Courgette | ||||
| 	ECourgette  Courgette `export:"true"` | ||||
| 	Pourgette   *Courgette | ||||
| 	EPourgette  *Courgette `export:"true"` | ||||
| 	Aubergine   map[string]string | ||||
| 	EAubergine  map[string]string `export:"true"` | ||||
| 	SAubergine  map[string]Tomate | ||||
| 	ESAubergine map[string]Tomate `export:"true"` | ||||
| 	PSAubergine map[string]*Tomate | ||||
| 	EPAubergine map[string]*Tomate `export:"true"` | ||||
| } | ||||
|  | ||||
| func Test_doOnStruct(t *testing.T) { | ||||
| 	testCase := []struct { | ||||
| 		name     string | ||||
| 		base     *Carotte | ||||
| 		expected *Carotte | ||||
| 		hasError bool | ||||
| 	}{ | ||||
| 		{ | ||||
| 			name: "primitive", | ||||
| 			base: &Carotte{ | ||||
| 				Name:  "koko", | ||||
| 				Value: 666, | ||||
| 			}, | ||||
| 			expected: &Carotte{ | ||||
| 				Name: "xxxx", | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name: "struct", | ||||
| 			base: &Carotte{ | ||||
| 				Name: "koko", | ||||
| 				Courgette: Courgette{ | ||||
| 					Ji: "huu", | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: &Carotte{ | ||||
| 				Name: "xxxx", | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name: "pointer", | ||||
| 			base: &Carotte{ | ||||
| 				Name: "koko", | ||||
| 				Pourgette: &Courgette{ | ||||
| 					Ji: "hoo", | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: &Carotte{ | ||||
| 				Name:      "xxxx", | ||||
| 				Pourgette: nil, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name: "export struct", | ||||
| 			base: &Carotte{ | ||||
| 				Name: "koko", | ||||
| 				ECourgette: Courgette{ | ||||
| 					Ji: "huu", | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: &Carotte{ | ||||
| 				Name: "xxxx", | ||||
| 				ECourgette: Courgette{ | ||||
| 					Ji: "xxxx", | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name: "export pointer struct", | ||||
| 			base: &Carotte{ | ||||
| 				Name: "koko", | ||||
| 				ECourgette: Courgette{ | ||||
| 					Ji: "huu", | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: &Carotte{ | ||||
| 				Name: "xxxx", | ||||
| 				ECourgette: Courgette{ | ||||
| 					Ji: "xxxx", | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name: "export map string/string", | ||||
| 			base: &Carotte{ | ||||
| 				Name: "koko", | ||||
| 				EAubergine: map[string]string{ | ||||
| 					"foo": "bar", | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: &Carotte{ | ||||
| 				Name: "xxxx", | ||||
| 				EAubergine: map[string]string{ | ||||
| 					"foo": "bar", | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name: "export map string/pointer", | ||||
| 			base: &Carotte{ | ||||
| 				Name: "koko", | ||||
| 				EPAubergine: map[string]*Tomate{ | ||||
| 					"foo": { | ||||
| 						Ji: "fdskljf", | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: &Carotte{ | ||||
| 				Name: "xxxx", | ||||
| 				EPAubergine: map[string]*Tomate{ | ||||
| 					"foo": { | ||||
| 						Ji: "xxxx", | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name: "export map string/struct (UNSAFE)", | ||||
| 			base: &Carotte{ | ||||
| 				Name: "koko", | ||||
| 				ESAubergine: map[string]Tomate{ | ||||
| 					"foo": { | ||||
| 						Ji: "JiJiJi", | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: &Carotte{ | ||||
| 				Name: "xxxx", | ||||
| 				ESAubergine: map[string]Tomate{ | ||||
| 					"foo": { | ||||
| 						Ji: "JiJiJi", | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 			hasError: true, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range testCase { | ||||
| 		t.Run(test.name, func(t *testing.T) { | ||||
| 			val := reflect.ValueOf(test.base).Elem() | ||||
| 			err := doOnStruct(val) | ||||
| 			if !test.hasError && err != nil { | ||||
| 				t.Fatal(err) | ||||
| 			} | ||||
| 			if test.hasError && err == nil { | ||||
| 				t.Fatal("Got no error but want an error.") | ||||
| 			} | ||||
|  | ||||
| 			assert.EqualValues(t, test.expected, test.base) | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
| @@ -1,22 +0,0 @@ | ||||
| package api | ||||
|  | ||||
| import ( | ||||
| 	"net/http" | ||||
|  | ||||
| 	"github.com/containous/mux" | ||||
| 	"github.com/containous/traefik/autogen/genstatic" | ||||
| 	"github.com/elazarl/go-bindata-assetfs" | ||||
| ) | ||||
|  | ||||
| // DashboardHandler expose dashboard routes | ||||
| type DashboardHandler struct{} | ||||
|  | ||||
| // AddRoutes add dashboard routes on a router | ||||
| func (g DashboardHandler) AddRoutes(router *mux.Router) { | ||||
| 	// Expose dashboard | ||||
| 	router.Methods(http.MethodGet).Path("/").HandlerFunc(func(response http.ResponseWriter, request *http.Request) { | ||||
| 		http.Redirect(response, request, request.Header.Get("X-Forwarded-Prefix")+"/dashboard/", 302) | ||||
| 	}) | ||||
| 	router.Methods(http.MethodGet).PathPrefix("/dashboard/"). | ||||
| 		Handler(http.StripPrefix("/dashboard/", http.FileServer(&assetfs.AssetFS{Asset: genstatic.Asset, AssetInfo: genstatic.AssetInfo, AssetDir: genstatic.AssetDir, Prefix: "static"}))) | ||||
| } | ||||
							
								
								
									
										46
									
								
								api/debug.go
									
									
									
									
									
								
							
							
						
						
									
										46
									
								
								api/debug.go
									
									
									
									
									
								
							| @@ -1,46 +0,0 @@ | ||||
| package api | ||||
|  | ||||
| import ( | ||||
| 	"expvar" | ||||
| 	"fmt" | ||||
| 	"net/http" | ||||
| 	"net/http/pprof" | ||||
| 	"runtime" | ||||
|  | ||||
| 	"github.com/containous/mux" | ||||
| ) | ||||
|  | ||||
| func init() { | ||||
| 	expvar.Publish("Goroutines", expvar.Func(goroutines)) | ||||
| } | ||||
|  | ||||
| func goroutines() interface{} { | ||||
| 	return runtime.NumGoroutine() | ||||
| } | ||||
|  | ||||
| // DebugHandler expose debug routes | ||||
| type DebugHandler struct{} | ||||
|  | ||||
| // AddRoutes add debug routes on a router | ||||
| func (g DebugHandler) AddRoutes(router *mux.Router) { | ||||
| 	router.Methods(http.MethodGet).Path("/debug/vars"). | ||||
| 		HandlerFunc(func(w http.ResponseWriter, _ *http.Request) { | ||||
| 			w.Header().Set("Content-Type", "application/json; charset=utf-8") | ||||
| 			fmt.Fprint(w, "{\n") | ||||
| 			first := true | ||||
| 			expvar.Do(func(kv expvar.KeyValue) { | ||||
| 				if !first { | ||||
| 					fmt.Fprint(w, ",\n") | ||||
| 				} | ||||
| 				first = false | ||||
| 				fmt.Fprintf(w, "%q: %s", kv.Key, kv.Value) | ||||
| 			}) | ||||
| 			fmt.Fprint(w, "\n}\n") | ||||
| 		}) | ||||
|  | ||||
| 	router.Methods(http.MethodGet).PathPrefix("/debug/pprof/cmdline").HandlerFunc(pprof.Cmdline) | ||||
| 	router.Methods(http.MethodGet).PathPrefix("/debug/pprof/profile").HandlerFunc(pprof.Profile) | ||||
| 	router.Methods(http.MethodGet).PathPrefix("/debug/pprof/symbol").HandlerFunc(pprof.Symbol) | ||||
| 	router.Methods(http.MethodGet).PathPrefix("/debug/pprof/trace").HandlerFunc(pprof.Trace) | ||||
| 	router.Methods(http.MethodGet).PathPrefix("/debug/pprof/").HandlerFunc(pprof.Index) | ||||
| } | ||||
							
								
								
									
										250
									
								
								api/handler.go
									
									
									
									
									
								
							
							
						
						
									
										250
									
								
								api/handler.go
									
									
									
									
									
								
							| @@ -1,250 +0,0 @@ | ||||
| package api | ||||
|  | ||||
| import ( | ||||
| 	"net/http" | ||||
|  | ||||
| 	"github.com/containous/mux" | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/middlewares" | ||||
| 	"github.com/containous/traefik/safe" | ||||
| 	"github.com/containous/traefik/types" | ||||
| 	"github.com/containous/traefik/version" | ||||
| 	thoas_stats "github.com/thoas/stats" | ||||
| 	"github.com/unrolled/render" | ||||
| ) | ||||
|  | ||||
| // Handler expose api routes | ||||
| type Handler struct { | ||||
| 	EntryPoint            string `description:"EntryPoint" export:"true"` | ||||
| 	Dashboard             bool   `description:"Activate dashboard" export:"true"` | ||||
| 	Debug                 bool   `export:"true"` | ||||
| 	CurrentConfigurations *safe.Safe | ||||
| 	Statistics            *types.Statistics          `description:"Enable more detailed statistics" export:"true"` | ||||
| 	Stats                 *thoas_stats.Stats         `json:"-"` | ||||
| 	StatsRecorder         *middlewares.StatsRecorder `json:"-"` | ||||
| } | ||||
|  | ||||
| var ( | ||||
| 	templatesRenderer = render.New(render.Options{ | ||||
| 		Directory: "nowhere", | ||||
| 	}) | ||||
| ) | ||||
|  | ||||
| // AddRoutes add api routes on a router | ||||
| func (p Handler) AddRoutes(router *mux.Router) { | ||||
| 	if p.Debug { | ||||
| 		DebugHandler{}.AddRoutes(router) | ||||
| 	} | ||||
|  | ||||
| 	router.Methods(http.MethodGet).Path("/api").HandlerFunc(p.getConfigHandler) | ||||
| 	router.Methods(http.MethodGet).Path("/api/providers").HandlerFunc(p.getConfigHandler) | ||||
| 	router.Methods(http.MethodGet).Path("/api/providers/{provider}").HandlerFunc(p.getProviderHandler) | ||||
| 	router.Methods(http.MethodGet).Path("/api/providers/{provider}/backends").HandlerFunc(p.getBackendsHandler) | ||||
| 	router.Methods(http.MethodGet).Path("/api/providers/{provider}/backends/{backend}").HandlerFunc(p.getBackendHandler) | ||||
| 	router.Methods(http.MethodGet).Path("/api/providers/{provider}/backends/{backend}/servers").HandlerFunc(p.getServersHandler) | ||||
| 	router.Methods(http.MethodGet).Path("/api/providers/{provider}/backends/{backend}/servers/{server}").HandlerFunc(p.getServerHandler) | ||||
| 	router.Methods(http.MethodGet).Path("/api/providers/{provider}/frontends").HandlerFunc(p.getFrontendsHandler) | ||||
| 	router.Methods(http.MethodGet).Path("/api/providers/{provider}/frontends/{frontend}").HandlerFunc(p.getFrontendHandler) | ||||
| 	router.Methods(http.MethodGet).Path("/api/providers/{provider}/frontends/{frontend}/routes").HandlerFunc(p.getRoutesHandler) | ||||
| 	router.Methods(http.MethodGet).Path("/api/providers/{provider}/frontends/{frontend}/routes/{route}").HandlerFunc(p.getRouteHandler) | ||||
|  | ||||
| 	// health route | ||||
| 	router.Methods(http.MethodGet).Path("/health").HandlerFunc(p.getHealthHandler) | ||||
|  | ||||
| 	version.Handler{}.AddRoutes(router) | ||||
|  | ||||
| 	if p.Dashboard { | ||||
| 		DashboardHandler{}.AddRoutes(router) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func getProviderIDFromVars(vars map[string]string) string { | ||||
| 	providerID := vars["provider"] | ||||
| 	// TODO: Deprecated | ||||
| 	if providerID == "rest" { | ||||
| 		providerID = "web" | ||||
| 	} | ||||
| 	return providerID | ||||
| } | ||||
|  | ||||
| func (p Handler) getConfigHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	currentConfigurations := p.CurrentConfigurations.Get().(types.Configurations) | ||||
| 	err := templatesRenderer.JSON(response, http.StatusOK, currentConfigurations) | ||||
| 	if err != nil { | ||||
| 		log.Error(err) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func (p Handler) getProviderHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	providerID := getProviderIDFromVars(mux.Vars(request)) | ||||
|  | ||||
| 	currentConfigurations := p.CurrentConfigurations.Get().(types.Configurations) | ||||
| 	if provider, ok := currentConfigurations[providerID]; ok { | ||||
| 		err := templatesRenderer.JSON(response, http.StatusOK, provider) | ||||
| 		if err != nil { | ||||
| 			log.Error(err) | ||||
| 		} | ||||
| 	} else { | ||||
| 		http.NotFound(response, request) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func (p Handler) getBackendsHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	providerID := getProviderIDFromVars(mux.Vars(request)) | ||||
|  | ||||
| 	currentConfigurations := p.CurrentConfigurations.Get().(types.Configurations) | ||||
| 	if provider, ok := currentConfigurations[providerID]; ok { | ||||
| 		err := templatesRenderer.JSON(response, http.StatusOK, provider.Backends) | ||||
| 		if err != nil { | ||||
| 			log.Error(err) | ||||
| 		} | ||||
| 	} else { | ||||
| 		http.NotFound(response, request) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func (p Handler) getBackendHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	vars := mux.Vars(request) | ||||
| 	providerID := getProviderIDFromVars(vars) | ||||
| 	backendID := vars["backend"] | ||||
|  | ||||
| 	currentConfigurations := p.CurrentConfigurations.Get().(types.Configurations) | ||||
| 	if provider, ok := currentConfigurations[providerID]; ok { | ||||
| 		if backend, ok := provider.Backends[backendID]; ok { | ||||
| 			err := templatesRenderer.JSON(response, http.StatusOK, backend) | ||||
| 			if err != nil { | ||||
| 				log.Error(err) | ||||
| 			} | ||||
| 			return | ||||
| 		} | ||||
| 	} | ||||
| 	http.NotFound(response, request) | ||||
| } | ||||
|  | ||||
| func (p Handler) getServersHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	vars := mux.Vars(request) | ||||
| 	providerID := getProviderIDFromVars(vars) | ||||
| 	backendID := vars["backend"] | ||||
|  | ||||
| 	currentConfigurations := p.CurrentConfigurations.Get().(types.Configurations) | ||||
| 	if provider, ok := currentConfigurations[providerID]; ok { | ||||
| 		if backend, ok := provider.Backends[backendID]; ok { | ||||
| 			err := templatesRenderer.JSON(response, http.StatusOK, backend.Servers) | ||||
| 			if err != nil { | ||||
| 				log.Error(err) | ||||
| 			} | ||||
| 			return | ||||
| 		} | ||||
| 	} | ||||
| 	http.NotFound(response, request) | ||||
| } | ||||
|  | ||||
| func (p Handler) getServerHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	vars := mux.Vars(request) | ||||
| 	providerID := getProviderIDFromVars(vars) | ||||
| 	backendID := vars["backend"] | ||||
| 	serverID := vars["server"] | ||||
|  | ||||
| 	currentConfigurations := p.CurrentConfigurations.Get().(types.Configurations) | ||||
| 	if provider, ok := currentConfigurations[providerID]; ok { | ||||
| 		if backend, ok := provider.Backends[backendID]; ok { | ||||
| 			if server, ok := backend.Servers[serverID]; ok { | ||||
| 				err := templatesRenderer.JSON(response, http.StatusOK, server) | ||||
| 				if err != nil { | ||||
| 					log.Error(err) | ||||
| 				} | ||||
| 				return | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| 	http.NotFound(response, request) | ||||
| } | ||||
|  | ||||
| func (p Handler) getFrontendsHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	providerID := getProviderIDFromVars(mux.Vars(request)) | ||||
|  | ||||
| 	currentConfigurations := p.CurrentConfigurations.Get().(types.Configurations) | ||||
| 	if provider, ok := currentConfigurations[providerID]; ok { | ||||
| 		err := templatesRenderer.JSON(response, http.StatusOK, provider.Frontends) | ||||
| 		if err != nil { | ||||
| 			log.Error(err) | ||||
| 		} | ||||
| 	} else { | ||||
| 		http.NotFound(response, request) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func (p Handler) getFrontendHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	vars := mux.Vars(request) | ||||
| 	providerID := getProviderIDFromVars(vars) | ||||
| 	frontendID := vars["frontend"] | ||||
|  | ||||
| 	currentConfigurations := p.CurrentConfigurations.Get().(types.Configurations) | ||||
| 	if provider, ok := currentConfigurations[providerID]; ok { | ||||
| 		if frontend, ok := provider.Frontends[frontendID]; ok { | ||||
| 			err := templatesRenderer.JSON(response, http.StatusOK, frontend) | ||||
| 			if err != nil { | ||||
| 				log.Error(err) | ||||
| 			} | ||||
| 			return | ||||
| 		} | ||||
| 	} | ||||
| 	http.NotFound(response, request) | ||||
| } | ||||
|  | ||||
| func (p Handler) getRoutesHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	vars := mux.Vars(request) | ||||
| 	providerID := getProviderIDFromVars(vars) | ||||
| 	frontendID := vars["frontend"] | ||||
|  | ||||
| 	currentConfigurations := p.CurrentConfigurations.Get().(types.Configurations) | ||||
| 	if provider, ok := currentConfigurations[providerID]; ok { | ||||
| 		if frontend, ok := provider.Frontends[frontendID]; ok { | ||||
| 			err := templatesRenderer.JSON(response, http.StatusOK, frontend.Routes) | ||||
| 			if err != nil { | ||||
| 				log.Error(err) | ||||
| 			} | ||||
| 			return | ||||
| 		} | ||||
| 	} | ||||
| 	http.NotFound(response, request) | ||||
| } | ||||
|  | ||||
| func (p Handler) getRouteHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	vars := mux.Vars(request) | ||||
| 	providerID := getProviderIDFromVars(vars) | ||||
| 	frontendID := vars["frontend"] | ||||
| 	routeID := vars["route"] | ||||
|  | ||||
| 	currentConfigurations := p.CurrentConfigurations.Get().(types.Configurations) | ||||
| 	if provider, ok := currentConfigurations[providerID]; ok { | ||||
| 		if frontend, ok := provider.Frontends[frontendID]; ok { | ||||
| 			if route, ok := frontend.Routes[routeID]; ok { | ||||
| 				err := templatesRenderer.JSON(response, http.StatusOK, route) | ||||
| 				if err != nil { | ||||
| 					log.Error(err) | ||||
| 				} | ||||
| 				return | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| 	http.NotFound(response, request) | ||||
| } | ||||
|  | ||||
| // healthResponse combines data returned by thoas/stats with statistics (if | ||||
| // they are enabled). | ||||
| type healthResponse struct { | ||||
| 	*thoas_stats.Data | ||||
| 	*middlewares.Stats | ||||
| } | ||||
|  | ||||
| func (p *Handler) getHealthHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	health := &healthResponse{Data: p.Stats.Data()} | ||||
| 	if p.StatsRecorder != nil { | ||||
| 		health.Stats = p.StatsRecorder.Data() | ||||
| 	} | ||||
| 	err := templatesRenderer.JSON(response, http.StatusOK, health) | ||||
| 	if err != nil { | ||||
| 		log.Error(err) | ||||
| 	} | ||||
| } | ||||
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							| @@ -1,27 +0,0 @@ | ||||
| FROM golang:1.10-alpine | ||||
|  | ||||
| RUN apk --update upgrade \ | ||||
| && apk --no-cache --no-progress add git mercurial bash gcc musl-dev curl tar \ | ||||
| && rm -rf /var/cache/apk/* | ||||
|  | ||||
| RUN go get github.com/containous/go-bindata/... \ | ||||
| && go get github.com/golang/lint/golint \ | ||||
| && go get github.com/kisielk/errcheck \ | ||||
| && go get github.com/client9/misspell/cmd/misspell | ||||
|  | ||||
| # Which docker version to test on | ||||
| ARG DOCKER_VERSION=17.03.2 | ||||
| ARG DEP_VERSION=0.4.1 | ||||
|  | ||||
| # Download dep binary to bin folder in $GOPATH | ||||
| RUN mkdir -p /usr/local/bin \ | ||||
|     && curl -fsSL -o /usr/local/bin/dep https://github.com/golang/dep/releases/download/v${DEP_VERSION}/dep-linux-amd64 \ | ||||
|     && chmod +x /usr/local/bin/dep | ||||
|  | ||||
| # Download docker | ||||
| RUN mkdir -p /usr/local/bin \ | ||||
|     && curl -fL https://download.docker.com/linux/static/stable/x86_64/docker-${DOCKER_VERSION}-ce.tgz \ | ||||
|     | tar -xzC /usr/local/bin --transform 's#^.+/##x' | ||||
|  | ||||
| WORKDIR /go/src/github.com/containous/traefik | ||||
| COPY . /go/src/github.com/containous/traefik | ||||
| @@ -1,247 +0,0 @@ | ||||
| package cluster | ||||
|  | ||||
| import ( | ||||
| 	"context" | ||||
| 	"encoding/json" | ||||
| 	"fmt" | ||||
| 	"sync" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/abronan/valkeyrie/store" | ||||
| 	"github.com/cenk/backoff" | ||||
| 	"github.com/containous/staert" | ||||
| 	"github.com/containous/traefik/job" | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/safe" | ||||
| 	"github.com/satori/go.uuid" | ||||
| ) | ||||
|  | ||||
| // Metadata stores Object plus metadata | ||||
| type Metadata struct { | ||||
| 	object Object | ||||
| 	Object []byte | ||||
| 	Lock   string | ||||
| } | ||||
|  | ||||
| // NewMetadata returns new Metadata | ||||
| func NewMetadata(object Object) *Metadata { | ||||
| 	return &Metadata{object: object} | ||||
| } | ||||
|  | ||||
| // Marshall marshalls object | ||||
| func (m *Metadata) Marshall() error { | ||||
| 	var err error | ||||
| 	m.Object, err = json.Marshal(m.object) | ||||
| 	return err | ||||
| } | ||||
|  | ||||
| func (m *Metadata) unmarshall() error { | ||||
| 	if len(m.Object) == 0 { | ||||
| 		return nil | ||||
| 	} | ||||
| 	return json.Unmarshal(m.Object, m.object) | ||||
| } | ||||
|  | ||||
| // Listener is called when Object has been changed in KV store | ||||
| type Listener func(Object) error | ||||
|  | ||||
| var _ Store = (*Datastore)(nil) | ||||
|  | ||||
| // Datastore holds a struct synced in a KV store | ||||
| type Datastore struct { | ||||
| 	kv        staert.KvSource | ||||
| 	ctx       context.Context | ||||
| 	localLock *sync.RWMutex | ||||
| 	meta      *Metadata | ||||
| 	lockKey   string | ||||
| 	listener  Listener | ||||
| } | ||||
|  | ||||
| // NewDataStore creates a Datastore | ||||
| func NewDataStore(ctx context.Context, kvSource staert.KvSource, object Object, listener Listener) (*Datastore, error) { | ||||
| 	datastore := Datastore{ | ||||
| 		kv:        kvSource, | ||||
| 		ctx:       ctx, | ||||
| 		meta:      &Metadata{object: object}, | ||||
| 		lockKey:   kvSource.Prefix + "/lock", | ||||
| 		localLock: &sync.RWMutex{}, | ||||
| 		listener:  listener, | ||||
| 	} | ||||
| 	err := datastore.watchChanges() | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	return &datastore, nil | ||||
| } | ||||
|  | ||||
| func (d *Datastore) watchChanges() error { | ||||
| 	stopCh := make(chan struct{}) | ||||
| 	kvCh, err := d.kv.Watch(d.lockKey, stopCh, nil) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	safe.Go(func() { | ||||
| 		ctx, cancel := context.WithCancel(d.ctx) | ||||
| 		operation := func() error { | ||||
| 			for { | ||||
| 				select { | ||||
| 				case <-ctx.Done(): | ||||
| 					stopCh <- struct{}{} | ||||
| 					return nil | ||||
| 				case _, ok := <-kvCh: | ||||
| 					if !ok { | ||||
| 						cancel() | ||||
| 						return err | ||||
| 					} | ||||
| 					err = d.reload() | ||||
| 					if err != nil { | ||||
| 						return err | ||||
| 					} | ||||
| 					if d.listener != nil { | ||||
| 						err := d.listener(d.meta.object) | ||||
| 						if err != nil { | ||||
| 							log.Errorf("Error calling datastore listener: %s", err) | ||||
| 						} | ||||
| 					} | ||||
| 				} | ||||
| 			} | ||||
| 		} | ||||
| 		notify := func(err error, time time.Duration) { | ||||
| 			log.Errorf("Error in watch datastore: %+v, retrying in %s", err, time) | ||||
| 		} | ||||
| 		err := backoff.RetryNotify(safe.OperationWithRecover(operation), job.NewBackOff(backoff.NewExponentialBackOff()), notify) | ||||
| 		if err != nil { | ||||
| 			log.Errorf("Error in watch datastore: %v", err) | ||||
| 		} | ||||
| 	}) | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func (d *Datastore) reload() error { | ||||
| 	log.Debug("Datastore reload") | ||||
| 	_, err := d.Load() | ||||
| 	return err | ||||
| } | ||||
|  | ||||
| // Begin creates a transaction with the KV store. | ||||
| func (d *Datastore) Begin() (Transaction, Object, error) { | ||||
| 	id := uuid.NewV4().String() | ||||
| 	log.Debugf("Transaction %s begins", id) | ||||
| 	remoteLock, err := d.kv.NewLock(d.lockKey, &store.LockOptions{TTL: 20 * time.Second, Value: []byte(id)}) | ||||
| 	if err != nil { | ||||
| 		return nil, nil, err | ||||
| 	} | ||||
| 	stopCh := make(chan struct{}) | ||||
| 	ctx, cancel := context.WithCancel(d.ctx) | ||||
| 	var errLock error | ||||
| 	go func() { | ||||
| 		_, errLock = remoteLock.Lock(stopCh) | ||||
| 		cancel() | ||||
| 	}() | ||||
| 	select { | ||||
| 	case <-ctx.Done(): | ||||
| 		if errLock != nil { | ||||
| 			return nil, nil, errLock | ||||
| 		} | ||||
| 	case <-d.ctx.Done(): | ||||
| 		stopCh <- struct{}{} | ||||
| 		return nil, nil, d.ctx.Err() | ||||
| 	} | ||||
|  | ||||
| 	// we got the lock! Now make sure we are synced with KV store | ||||
| 	operation := func() error { | ||||
| 		meta := d.get() | ||||
| 		if meta.Lock != id { | ||||
| 			return fmt.Errorf("Object lock value: expected %s, got %s", id, meta.Lock) | ||||
| 		} | ||||
| 		return nil | ||||
| 	} | ||||
| 	notify := func(err error, time time.Duration) { | ||||
| 		log.Errorf("Datastore sync error: %v, retrying in %s", err, time) | ||||
| 		err = d.reload() | ||||
| 		if err != nil { | ||||
| 			log.Errorf("Error reloading: %+v", err) | ||||
| 		} | ||||
| 	} | ||||
| 	ebo := backoff.NewExponentialBackOff() | ||||
| 	ebo.MaxElapsedTime = 60 * time.Second | ||||
| 	err = backoff.RetryNotify(safe.OperationWithRecover(operation), ebo, notify) | ||||
| 	if err != nil { | ||||
| 		return nil, nil, fmt.Errorf("Datastore cannot sync: %v", err) | ||||
| 	} | ||||
|  | ||||
| 	// we synced with KV store, we can now return Setter | ||||
| 	return &datastoreTransaction{ | ||||
| 		Datastore:  d, | ||||
| 		remoteLock: remoteLock, | ||||
| 		id:         id, | ||||
| 	}, d.meta.object, nil | ||||
| } | ||||
|  | ||||
| func (d *Datastore) get() *Metadata { | ||||
| 	d.localLock.RLock() | ||||
| 	defer d.localLock.RUnlock() | ||||
| 	return d.meta | ||||
| } | ||||
|  | ||||
| // Load load atomically a struct from the KV store | ||||
| func (d *Datastore) Load() (Object, error) { | ||||
| 	d.localLock.Lock() | ||||
| 	defer d.localLock.Unlock() | ||||
|  | ||||
| 	// clear Object first, as mapstructure's decoder doesn't have ZeroFields set to true for merging purposes | ||||
| 	d.meta.Object = d.meta.Object[:0] | ||||
|  | ||||
| 	err := d.kv.LoadConfig(d.meta) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	err = d.meta.unmarshall() | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	return d.meta.object, nil | ||||
| } | ||||
|  | ||||
| // Get atomically a struct from the KV store | ||||
| func (d *Datastore) Get() Object { | ||||
| 	d.localLock.RLock() | ||||
| 	defer d.localLock.RUnlock() | ||||
| 	return d.meta.object | ||||
| } | ||||
|  | ||||
| var _ Transaction = (*datastoreTransaction)(nil) | ||||
|  | ||||
| type datastoreTransaction struct { | ||||
| 	*Datastore | ||||
| 	remoteLock store.Locker | ||||
| 	dirty      bool | ||||
| 	id         string | ||||
| } | ||||
|  | ||||
| // Commit allows to set an object in the KV store | ||||
| func (s *datastoreTransaction) Commit(object Object) error { | ||||
| 	s.localLock.Lock() | ||||
| 	defer s.localLock.Unlock() | ||||
| 	if s.dirty { | ||||
| 		return fmt.Errorf("Transaction already used, please begin a new one") | ||||
| 	} | ||||
| 	s.Datastore.meta.object = object | ||||
| 	err := s.Datastore.meta.Marshall() | ||||
| 	if err != nil { | ||||
| 		return fmt.Errorf("Marshall error: %s", err) | ||||
| 	} | ||||
| 	err = s.kv.StoreConfig(s.Datastore.meta) | ||||
| 	if err != nil { | ||||
| 		return fmt.Errorf("StoreConfig error: %s", err) | ||||
| 	} | ||||
|  | ||||
| 	err = s.remoteLock.Unlock() | ||||
| 	if err != nil { | ||||
| 		return fmt.Errorf("Unlock error: %s", err) | ||||
| 	} | ||||
|  | ||||
| 	s.dirty = true | ||||
| 	log.Debugf("Transaction committed %s", s.id) | ||||
| 	return nil | ||||
| } | ||||
| @@ -1,136 +0,0 @@ | ||||
| package cluster | ||||
|  | ||||
| import ( | ||||
| 	"context" | ||||
| 	"net/http" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/cenk/backoff" | ||||
| 	"github.com/containous/mux" | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/safe" | ||||
| 	"github.com/containous/traefik/types" | ||||
| 	"github.com/docker/leadership" | ||||
| 	"github.com/unrolled/render" | ||||
| ) | ||||
|  | ||||
| var templatesRenderer = render.New(render.Options{ | ||||
| 	Directory: "nowhere", | ||||
| }) | ||||
|  | ||||
| // Leadership allows leadership election using a KV store | ||||
| type Leadership struct { | ||||
| 	*safe.Pool | ||||
| 	*types.Cluster | ||||
| 	candidate *leadership.Candidate | ||||
| 	leader    *safe.Safe | ||||
| 	listeners []LeaderListener | ||||
| } | ||||
|  | ||||
| // NewLeadership creates a leadership | ||||
| func NewLeadership(ctx context.Context, cluster *types.Cluster) *Leadership { | ||||
| 	return &Leadership{ | ||||
| 		Pool:      safe.NewPool(ctx), | ||||
| 		Cluster:   cluster, | ||||
| 		candidate: leadership.NewCandidate(cluster.Store, cluster.Store.Prefix+"/leader", cluster.Node, 20*time.Second), | ||||
| 		listeners: []LeaderListener{}, | ||||
| 		leader:    safe.New(false), | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // LeaderListener is called when leadership has changed | ||||
| type LeaderListener func(elected bool) error | ||||
|  | ||||
| // Participate tries to be a leader | ||||
| func (l *Leadership) Participate(pool *safe.Pool) { | ||||
| 	pool.GoCtx(func(ctx context.Context) { | ||||
| 		log.Debugf("Node %s running for election", l.Cluster.Node) | ||||
| 		defer log.Debugf("Node %s no more running for election", l.Cluster.Node) | ||||
| 		backOff := backoff.NewExponentialBackOff() | ||||
| 		operation := func() error { | ||||
| 			return l.run(ctx, l.candidate) | ||||
| 		} | ||||
|  | ||||
| 		notify := func(err error, time time.Duration) { | ||||
| 			log.Errorf("Leadership election error %+v, retrying in %s", err, time) | ||||
| 		} | ||||
| 		err := backoff.RetryNotify(safe.OperationWithRecover(operation), backOff, notify) | ||||
| 		if err != nil { | ||||
| 			log.Errorf("Cannot elect leadership %+v", err) | ||||
| 		} | ||||
| 	}) | ||||
| } | ||||
|  | ||||
| // AddListener adds a leadership listener | ||||
| func (l *Leadership) AddListener(listener LeaderListener) { | ||||
| 	l.listeners = append(l.listeners, listener) | ||||
| } | ||||
|  | ||||
| // Resign resigns from being a leader | ||||
| func (l *Leadership) Resign() { | ||||
| 	l.candidate.Resign() | ||||
| 	log.Infof("Node %s resigned", l.Cluster.Node) | ||||
| } | ||||
|  | ||||
| func (l *Leadership) run(ctx context.Context, candidate *leadership.Candidate) error { | ||||
| 	electedCh, errCh := candidate.RunForElection() | ||||
| 	for { | ||||
| 		select { | ||||
| 		case elected := <-electedCh: | ||||
| 			l.onElection(elected) | ||||
| 		case err := <-errCh: | ||||
| 			return err | ||||
| 		case <-ctx.Done(): | ||||
| 			l.candidate.Resign() | ||||
| 			return nil | ||||
| 		} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func (l *Leadership) onElection(elected bool) { | ||||
| 	if elected { | ||||
| 		log.Infof("Node %s elected leader ♚", l.Cluster.Node) | ||||
| 		l.leader.Set(true) | ||||
| 		l.Start() | ||||
| 	} else { | ||||
| 		log.Infof("Node %s elected worker ♝", l.Cluster.Node) | ||||
| 		l.leader.Set(false) | ||||
| 		l.Stop() | ||||
| 	} | ||||
| 	for _, listener := range l.listeners { | ||||
| 		err := listener(elected) | ||||
| 		if err != nil { | ||||
| 			log.Errorf("Error calling Leadership listener: %s", err) | ||||
| 		} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| type leaderResponse struct { | ||||
| 	Leader bool `json:"leader"` | ||||
| } | ||||
|  | ||||
| func (l *Leadership) getLeaderHandler(response http.ResponseWriter, request *http.Request) { | ||||
| 	leader := &leaderResponse{Leader: l.IsLeader()} | ||||
|  | ||||
| 	status := http.StatusOK | ||||
| 	if !leader.Leader { | ||||
| 		// Set status to be `429`, as this will typically cause load balancers to stop sending requests to the instance without removing them from rotation. | ||||
| 		status = http.StatusTooManyRequests | ||||
| 	} | ||||
|  | ||||
| 	err := templatesRenderer.JSON(response, status, leader) | ||||
| 	if err != nil { | ||||
| 		log.Error(err) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // IsLeader returns true if current node is leader | ||||
| func (l *Leadership) IsLeader() bool { | ||||
| 	return l.leader.Get().(bool) | ||||
| } | ||||
|  | ||||
| // AddRoutes add dashboard routes on a router | ||||
| func (l *Leadership) AddRoutes(router *mux.Router) { | ||||
| 	// Expose cluster leader | ||||
| 	router.Methods(http.MethodGet).Path("/api/cluster/leader").HandlerFunc(l.getLeaderHandler) | ||||
| } | ||||
| @@ -1,16 +0,0 @@ | ||||
| package cluster | ||||
|  | ||||
| // Object is the struct to store | ||||
| type Object interface{} | ||||
|  | ||||
| // Store is a generic interface to represents a storage | ||||
| type Store interface { | ||||
| 	Load() (Object, error) | ||||
| 	Get() Object | ||||
| 	Begin() (Transaction, Object, error) | ||||
| } | ||||
|  | ||||
| // Transaction allows to set a struct in the KV store | ||||
| type Transaction interface { | ||||
| 	Commit(object Object) error | ||||
| } | ||||
							
								
								
									
										171
									
								
								cmd/bug/bug.go
									
									
									
									
									
								
							
							
						
						
									
										171
									
								
								cmd/bug/bug.go
									
									
									
									
									
								
							| @@ -1,171 +0,0 @@ | ||||
| package bug | ||||
|  | ||||
| import ( | ||||
| 	"bytes" | ||||
| 	"fmt" | ||||
| 	"net/url" | ||||
| 	"os/exec" | ||||
| 	"runtime" | ||||
| 	"text/template" | ||||
|  | ||||
| 	"github.com/containous/flaeg" | ||||
| 	"github.com/containous/traefik/anonymize" | ||||
| 	"github.com/containous/traefik/cmd" | ||||
| 	"github.com/containous/traefik/cmd/version" | ||||
| ) | ||||
|  | ||||
| const ( | ||||
| 	bugTracker  = "https://github.com/containous/traefik/issues/new" | ||||
| 	bugTemplate = `<!-- | ||||
| DO NOT FILE ISSUES FOR GENERAL SUPPORT QUESTIONS. | ||||
|  | ||||
| The issue tracker is for reporting bugs and feature requests only. | ||||
| For end-user related support questions, refer to one of the following: | ||||
|  | ||||
| - Stack Overflow (using the "traefik" tag): https://stackoverflow.com/questions/tagged/traefik | ||||
| - the Traefik community Slack channel: https://traefik.herokuapp.com | ||||
|  | ||||
| --> | ||||
|  | ||||
| ### Do you want to request a *feature* or report a *bug*? | ||||
|  | ||||
| (If you intend to ask a support question: **DO NOT FILE AN ISSUE**. | ||||
| Use [Stack Overflow](https://stackoverflow.com/questions/tagged/traefik) | ||||
| or [Slack](https://traefik.herokuapp.com) instead.) | ||||
|  | ||||
|  | ||||
|  | ||||
| ### What did you do? | ||||
|  | ||||
| <!-- | ||||
|  | ||||
| HOW TO WRITE A GOOD ISSUE? | ||||
|  | ||||
| - Respect the issue template as more as possible. | ||||
| - If it's possible use the command ` + "`" + "traefik bug" + "`" + `. See https://www.youtube.com/watch?v=Lyz62L8m93I. | ||||
| - The title must be short and descriptive. | ||||
| - Explain the conditions which led you to write this issue: the context. | ||||
| - The context should lead to something, an idea or a problem that you’re facing. | ||||
| - Remain clear and concise. | ||||
| - Format your messages to help the reader focus on what matters and understand the structure of your message, use Markdown syntax https://help.github.com/articles/github-flavored-markdown | ||||
|  | ||||
| --> | ||||
|  | ||||
|  | ||||
| ### What did you expect to see? | ||||
|  | ||||
|  | ||||
|  | ||||
| ### What did you see instead? | ||||
|  | ||||
|  | ||||
|  | ||||
| ### Output of ` + "`" + `traefik version` + "`" + `: (_What version of Traefik are you using?_) | ||||
|  | ||||
| ` + "```" + ` | ||||
| {{.Version}} | ||||
| ` + "```" + ` | ||||
|  | ||||
| ### What is your environment & configuration (arguments, toml, provider, platform, ...)? | ||||
|  | ||||
| ` + "```" + `json | ||||
| {{.Configuration}} | ||||
| ` + "```" + ` | ||||
|  | ||||
| <!-- | ||||
| Add more configuration information here. | ||||
| --> | ||||
|  | ||||
| ### If applicable, please paste the log output at DEBUG level (` + "`" + `--logLevel=DEBUG` + "`" + ` switch) | ||||
|  | ||||
| ` + "```" + ` | ||||
| (paste your output here) | ||||
| ` + "```" + ` | ||||
|  | ||||
| ` | ||||
| ) | ||||
|  | ||||
| // NewCmd builds a new Bug command | ||||
| func NewCmd(traefikConfiguration *cmd.TraefikConfiguration, traefikPointersConfiguration *cmd.TraefikConfiguration) *flaeg.Command { | ||||
|  | ||||
| 	//version Command init | ||||
| 	return &flaeg.Command{ | ||||
| 		Name:                  "bug", | ||||
| 		Description:           `Report an issue on Traefik bugtracker`, | ||||
| 		Config:                traefikConfiguration, | ||||
| 		DefaultPointersConfig: traefikPointersConfiguration, | ||||
| 		Run: runCmd(traefikConfiguration), | ||||
| 		Metadata: map[string]string{ | ||||
| 			"parseAllSources": "true", | ||||
| 		}, | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func runCmd(traefikConfiguration *cmd.TraefikConfiguration) func() error { | ||||
| 	return func() error { | ||||
|  | ||||
| 		body, err := createReport(traefikConfiguration) | ||||
| 		if err != nil { | ||||
| 			return err | ||||
| 		} | ||||
|  | ||||
| 		sendReport(body) | ||||
|  | ||||
| 		return nil | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func createReport(traefikConfiguration *cmd.TraefikConfiguration) (string, error) { | ||||
| 	var versionPrint bytes.Buffer | ||||
| 	if err := version.GetPrint(&versionPrint); err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
|  | ||||
| 	tmpl, err := template.New("bug").Parse(bugTemplate) | ||||
| 	if err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
|  | ||||
| 	config, err := anonymize.Do(traefikConfiguration, true) | ||||
| 	if err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
|  | ||||
| 	v := struct { | ||||
| 		Version       string | ||||
| 		Configuration string | ||||
| 	}{ | ||||
| 		Version:       versionPrint.String(), | ||||
| 		Configuration: config, | ||||
| 	} | ||||
|  | ||||
| 	var bug bytes.Buffer | ||||
| 	if err := tmpl.Execute(&bug, v); err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
|  | ||||
| 	return bug.String(), nil | ||||
| } | ||||
|  | ||||
| func sendReport(body string) { | ||||
| 	URL := bugTracker + "?body=" + url.QueryEscape(body) | ||||
| 	if err := openBrowser(URL); err != nil { | ||||
| 		fmt.Printf("Please file a new issue at %s using this template:\n\n", bugTracker) | ||||
| 		fmt.Print(body) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func openBrowser(URL string) error { | ||||
| 	var err error | ||||
| 	switch runtime.GOOS { | ||||
| 	case "linux": | ||||
| 		err = exec.Command("xdg-open", URL).Start() | ||||
| 	case "windows": | ||||
| 		err = exec.Command("rundll32", "url.dll,FileProtocolHandler", URL).Start() | ||||
| 	case "darwin": | ||||
| 		err = exec.Command("open", URL).Start() | ||||
| 	default: | ||||
| 		err = fmt.Errorf("unsupported platform") | ||||
| 	} | ||||
| 	return err | ||||
| } | ||||
| @@ -1,67 +0,0 @@ | ||||
| package bug | ||||
|  | ||||
| import ( | ||||
| 	"testing" | ||||
|  | ||||
| 	"github.com/containous/traefik/anonymize" | ||||
| 	"github.com/containous/traefik/cmd" | ||||
| 	"github.com/containous/traefik/configuration" | ||||
| 	"github.com/containous/traefik/provider/file" | ||||
| 	"github.com/containous/traefik/tls" | ||||
| 	"github.com/containous/traefik/types" | ||||
| 	"github.com/stretchr/testify/assert" | ||||
| ) | ||||
|  | ||||
| func Test_createReport(t *testing.T) { | ||||
| 	traefikConfiguration := &cmd.TraefikConfiguration{ | ||||
| 		ConfigFile: "FOO", | ||||
| 		GlobalConfiguration: configuration.GlobalConfiguration{ | ||||
| 			EntryPoints: configuration.EntryPoints{ | ||||
| 				"goo": &configuration.EntryPoint{ | ||||
| 					Address: "hoo.bar", | ||||
| 					Auth: &types.Auth{ | ||||
| 						Basic: &types.Basic{ | ||||
| 							UsersFile: "foo Basic UsersFile", | ||||
| 							Users:     types.Users{"foo Basic Users 1", "foo Basic Users 2", "foo Basic Users 3"}, | ||||
| 						}, | ||||
| 						Digest: &types.Digest{ | ||||
| 							UsersFile: "foo Digest UsersFile", | ||||
| 							Users:     types.Users{"foo Digest Users 1", "foo Digest Users 2", "foo Digest Users 3"}, | ||||
| 						}, | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 			File: &file.Provider{ | ||||
| 				Directory: "BAR", | ||||
| 			}, | ||||
| 			RootCAs: tls.RootCAs{"fllf"}, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	report, err := createReport(traefikConfiguration) | ||||
| 	assert.NoError(t, err, report) | ||||
|  | ||||
| 	// exported anonymous configuration | ||||
| 	assert.NotContains(t, "web Basic Users ", report) | ||||
| 	assert.NotContains(t, "foo Digest Users ", report) | ||||
| 	assert.NotContains(t, "hoo.bar", report) | ||||
| } | ||||
|  | ||||
| func Test_anonymize_traefikConfiguration(t *testing.T) { | ||||
| 	traefikConfiguration := &cmd.TraefikConfiguration{ | ||||
| 		ConfigFile: "FOO", | ||||
| 		GlobalConfiguration: configuration.GlobalConfiguration{ | ||||
| 			EntryPoints: configuration.EntryPoints{ | ||||
| 				"goo": &configuration.EntryPoint{ | ||||
| 					Address: "hoo.bar", | ||||
| 				}, | ||||
| 			}, | ||||
| 			File: &file.Provider{ | ||||
| 				Directory: "BAR", | ||||
| 			}, | ||||
| 		}, | ||||
| 	} | ||||
| 	_, err := anonymize.Do(traefikConfiguration, true) | ||||
| 	assert.NoError(t, err) | ||||
| 	assert.Equal(t, "hoo.bar", traefikConfiguration.GlobalConfiguration.EntryPoints["goo"].Address) | ||||
| } | ||||
| @@ -3,321 +3,35 @@ package cmd | ||||
| import ( | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/containous/flaeg" | ||||
| 	"github.com/containous/traefik-extra-service-fabric" | ||||
| 	"github.com/containous/traefik/api" | ||||
| 	"github.com/containous/traefik/configuration" | ||||
| 	"github.com/containous/traefik/middlewares/accesslog" | ||||
| 	"github.com/containous/traefik/middlewares/tracing" | ||||
| 	"github.com/containous/traefik/middlewares/tracing/jaeger" | ||||
| 	"github.com/containous/traefik/middlewares/tracing/zipkin" | ||||
| 	"github.com/containous/traefik/ping" | ||||
| 	"github.com/containous/traefik/provider/boltdb" | ||||
| 	"github.com/containous/traefik/provider/consul" | ||||
| 	"github.com/containous/traefik/provider/consulcatalog" | ||||
| 	"github.com/containous/traefik/provider/docker" | ||||
| 	"github.com/containous/traefik/provider/dynamodb" | ||||
| 	"github.com/containous/traefik/provider/ecs" | ||||
| 	"github.com/containous/traefik/provider/etcd" | ||||
| 	"github.com/containous/traefik/provider/eureka" | ||||
| 	"github.com/containous/traefik/provider/file" | ||||
| 	"github.com/containous/traefik/provider/kubernetes" | ||||
| 	"github.com/containous/traefik/provider/marathon" | ||||
| 	"github.com/containous/traefik/provider/mesos" | ||||
| 	"github.com/containous/traefik/provider/rancher" | ||||
| 	"github.com/containous/traefik/provider/rest" | ||||
| 	"github.com/containous/traefik/provider/zk" | ||||
| 	"github.com/containous/traefik/types" | ||||
| 	sf "github.com/jjcollinge/servicefabric" | ||||
| 	ptypes "github.com/traefik/paerser/types" | ||||
| 	"github.com/traefik/traefik/v3/pkg/config/static" | ||||
| ) | ||||
|  | ||||
| // TraefikConfiguration holds GlobalConfiguration and other stuff | ||||
| type TraefikConfiguration struct { | ||||
| 	configuration.GlobalConfiguration `mapstructure:",squash" export:"true"` | ||||
| 	ConfigFile                        string `short:"c" description:"Configuration file to use (TOML)." export:"true"` | ||||
| // TraefikCmdConfiguration wraps the static configuration and extra parameters. | ||||
| type TraefikCmdConfiguration struct { | ||||
| 	static.Configuration `export:"true"` | ||||
| 	// ConfigFile is the path to the configuration file. | ||||
| 	ConfigFile string `description:"Configuration file to use. If specified all other flags are ignored." export:"true"` | ||||
| } | ||||
|  | ||||
| // NewTraefikDefaultPointersConfiguration creates a TraefikConfiguration with pointers default values | ||||
| func NewTraefikDefaultPointersConfiguration() *TraefikConfiguration { | ||||
| 	// default Docker | ||||
| 	var defaultDocker docker.Provider | ||||
| 	defaultDocker.Watch = true | ||||
| 	defaultDocker.ExposedByDefault = true | ||||
| 	defaultDocker.Endpoint = "unix:///var/run/docker.sock" | ||||
| 	defaultDocker.SwarmMode = false | ||||
|  | ||||
| 	// default File | ||||
| 	var defaultFile file.Provider | ||||
| 	defaultFile.Watch = true | ||||
| 	defaultFile.Filename = "" // needs equivalent to  viper.ConfigFileUsed() | ||||
|  | ||||
| 	// default Rest | ||||
| 	var defaultRest rest.Provider | ||||
| 	defaultRest.EntryPoint = configuration.DefaultInternalEntryPointName | ||||
|  | ||||
| 	// TODO: Deprecated - Web provider, use REST provider instead | ||||
| 	var defaultWeb configuration.WebCompatibility | ||||
| 	defaultWeb.Address = ":8080" | ||||
| 	defaultWeb.Statistics = &types.Statistics{ | ||||
| 		RecentErrors: 10, | ||||
| 	} | ||||
|  | ||||
| 	// TODO: Deprecated - default Metrics | ||||
| 	defaultWeb.Metrics = &types.Metrics{ | ||||
| 		Prometheus: &types.Prometheus{ | ||||
| 			Buckets:    types.Buckets{0.1, 0.3, 1.2, 5}, | ||||
| 			EntryPoint: configuration.DefaultInternalEntryPointName, | ||||
| 		}, | ||||
| 		Datadog: &types.Datadog{ | ||||
| 			Address:      "localhost:8125", | ||||
| 			PushInterval: "10s", | ||||
| 		}, | ||||
| 		StatsD: &types.Statsd{ | ||||
| 			Address:      "localhost:8125", | ||||
| 			PushInterval: "10s", | ||||
| 		}, | ||||
| 		InfluxDB: &types.InfluxDB{ | ||||
| 			Address:      "localhost:8089", | ||||
| 			PushInterval: "10s", | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	// default Marathon | ||||
| 	var defaultMarathon marathon.Provider | ||||
| 	defaultMarathon.Watch = true | ||||
| 	defaultMarathon.Endpoint = "http://127.0.0.1:8080" | ||||
| 	defaultMarathon.ExposedByDefault = true | ||||
| 	defaultMarathon.Constraints = types.Constraints{} | ||||
| 	defaultMarathon.DialerTimeout = flaeg.Duration(60 * time.Second) | ||||
| 	defaultMarathon.KeepAlive = flaeg.Duration(10 * time.Second) | ||||
|  | ||||
| 	// default Consul | ||||
| 	var defaultConsul consul.Provider | ||||
| 	defaultConsul.Watch = true | ||||
| 	defaultConsul.Endpoint = "127.0.0.1:8500" | ||||
| 	defaultConsul.Prefix = "traefik" | ||||
| 	defaultConsul.Constraints = types.Constraints{} | ||||
|  | ||||
| 	// default CatalogProvider | ||||
| 	var defaultConsulCatalog consulcatalog.Provider | ||||
| 	defaultConsulCatalog.Endpoint = "127.0.0.1:8500" | ||||
| 	defaultConsulCatalog.ExposedByDefault = true | ||||
| 	defaultConsulCatalog.Constraints = types.Constraints{} | ||||
| 	defaultConsulCatalog.Prefix = "traefik" | ||||
| 	defaultConsulCatalog.FrontEndRule = "Host:{{.ServiceName}}.{{.Domain}}" | ||||
|  | ||||
| 	// default Etcd | ||||
| 	var defaultEtcd etcd.Provider | ||||
| 	defaultEtcd.Watch = true | ||||
| 	defaultEtcd.Endpoint = "127.0.0.1:2379" | ||||
| 	defaultEtcd.Prefix = "/traefik" | ||||
| 	defaultEtcd.Constraints = types.Constraints{} | ||||
|  | ||||
| 	// default Zookeeper | ||||
| 	var defaultZookeeper zk.Provider | ||||
| 	defaultZookeeper.Watch = true | ||||
| 	defaultZookeeper.Endpoint = "127.0.0.1:2181" | ||||
| 	defaultZookeeper.Prefix = "traefik" | ||||
| 	defaultZookeeper.Constraints = types.Constraints{} | ||||
|  | ||||
| 	// default Boltdb | ||||
| 	var defaultBoltDb boltdb.Provider | ||||
| 	defaultBoltDb.Watch = true | ||||
| 	defaultBoltDb.Endpoint = "127.0.0.1:4001" | ||||
| 	defaultBoltDb.Prefix = "/traefik" | ||||
| 	defaultBoltDb.Constraints = types.Constraints{} | ||||
|  | ||||
| 	// default Kubernetes | ||||
| 	var defaultKubernetes kubernetes.Provider | ||||
| 	defaultKubernetes.Watch = true | ||||
| 	defaultKubernetes.Constraints = types.Constraints{} | ||||
|  | ||||
| 	// default Mesos | ||||
| 	var defaultMesos mesos.Provider | ||||
| 	defaultMesos.Watch = true | ||||
| 	defaultMesos.Endpoint = "http://127.0.0.1:5050" | ||||
| 	defaultMesos.ExposedByDefault = true | ||||
| 	defaultMesos.Constraints = types.Constraints{} | ||||
| 	defaultMesos.RefreshSeconds = 30 | ||||
| 	defaultMesos.ZkDetectionTimeout = 30 | ||||
| 	defaultMesos.StateTimeoutSecond = 30 | ||||
|  | ||||
| 	// default ECS | ||||
| 	var defaultECS ecs.Provider | ||||
| 	defaultECS.Watch = true | ||||
| 	defaultECS.ExposedByDefault = true | ||||
| 	defaultECS.AutoDiscoverClusters = false | ||||
| 	defaultECS.Clusters = ecs.Clusters{"default"} | ||||
| 	defaultECS.RefreshSeconds = 15 | ||||
| 	defaultECS.Constraints = types.Constraints{} | ||||
|  | ||||
| 	// default Rancher | ||||
| 	var defaultRancher rancher.Provider | ||||
| 	defaultRancher.Watch = true | ||||
| 	defaultRancher.ExposedByDefault = true | ||||
| 	defaultRancher.RefreshSeconds = 15 | ||||
|  | ||||
| 	// default DynamoDB | ||||
| 	var defaultDynamoDB dynamodb.Provider | ||||
| 	defaultDynamoDB.Constraints = types.Constraints{} | ||||
| 	defaultDynamoDB.RefreshSeconds = 15 | ||||
| 	defaultDynamoDB.TableName = "traefik" | ||||
| 	defaultDynamoDB.Watch = true | ||||
|  | ||||
| 	// default Eureka | ||||
| 	var defaultEureka eureka.Provider | ||||
| 	defaultEureka.RefreshSeconds = flaeg.Duration(30 * time.Second) | ||||
|  | ||||
| 	// default ServiceFabric | ||||
| 	var defaultServiceFabric servicefabric.Provider | ||||
| 	defaultServiceFabric.APIVersion = sf.DefaultAPIVersion | ||||
| 	defaultServiceFabric.RefreshSeconds = 10 | ||||
|  | ||||
| 	// default Ping | ||||
| 	var defaultPing = ping.Handler{ | ||||
| 		EntryPoint: "traefik", | ||||
| 	} | ||||
|  | ||||
| 	// default TraefikLog | ||||
| 	defaultTraefikLog := types.TraefikLog{ | ||||
| 		Format:   "common", | ||||
| 		FilePath: "", | ||||
| 	} | ||||
|  | ||||
| 	// default AccessLog | ||||
| 	defaultAccessLog := types.AccessLog{ | ||||
| 		Format:   accesslog.CommonFormat, | ||||
| 		FilePath: "", | ||||
| 		Filters:  &types.AccessLogFilters{}, | ||||
| 		Fields: &types.AccessLogFields{ | ||||
| 			DefaultMode: types.AccessLogKeep, | ||||
| 			Headers: &types.FieldHeaders{ | ||||
| 				DefaultMode: types.AccessLogKeep, | ||||
| // NewTraefikConfiguration creates a TraefikCmdConfiguration with default values. | ||||
| func NewTraefikConfiguration() *TraefikCmdConfiguration { | ||||
| 	return &TraefikCmdConfiguration{ | ||||
| 		Configuration: static.Configuration{ | ||||
| 			Global: &static.Global{ | ||||
| 				CheckNewVersion: true, | ||||
| 			}, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	// default HealthCheckConfig | ||||
| 	healthCheck := configuration.HealthCheckConfig{ | ||||
| 		Interval: flaeg.Duration(configuration.DefaultHealthCheckInterval), | ||||
| 	} | ||||
|  | ||||
| 	// default RespondingTimeouts | ||||
| 	respondingTimeouts := configuration.RespondingTimeouts{ | ||||
| 		IdleTimeout: flaeg.Duration(configuration.DefaultIdleTimeout), | ||||
| 	} | ||||
|  | ||||
| 	// default ForwardingTimeouts | ||||
| 	forwardingTimeouts := configuration.ForwardingTimeouts{ | ||||
| 		DialTimeout: flaeg.Duration(configuration.DefaultDialTimeout), | ||||
| 	} | ||||
|  | ||||
| 	// default Tracing | ||||
| 	defaultTracing := tracing.Tracing{ | ||||
| 		Backend:     "jaeger", | ||||
| 		ServiceName: "traefik", | ||||
| 		Jaeger: &jaeger.Config{ | ||||
| 			SamplingServerURL:  "http://localhost:5778/sampling", | ||||
| 			SamplingType:       "const", | ||||
| 			SamplingParam:      1.0, | ||||
| 			LocalAgentHostPort: "127.0.0.1:6832", | ||||
| 		}, | ||||
| 		Zipkin: &zipkin.Config{ | ||||
| 			HTTPEndpoint: "http://localhost:9411/api/v1/spans", | ||||
| 			SameSpan:     false, | ||||
| 			ID128Bit:     true, | ||||
| 			Debug:        false, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	// default LifeCycle | ||||
| 	defaultLifeCycle := configuration.LifeCycle{ | ||||
| 		GraceTimeOut: flaeg.Duration(configuration.DefaultGraceTimeout), | ||||
| 	} | ||||
|  | ||||
| 	// default ApiConfiguration | ||||
| 	defaultAPI := api.Handler{ | ||||
| 		EntryPoint: "traefik", | ||||
| 		Dashboard:  true, | ||||
| 	} | ||||
| 	defaultAPI.Statistics = &types.Statistics{ | ||||
| 		RecentErrors: 10, | ||||
| 	} | ||||
|  | ||||
| 	// default Metrics | ||||
| 	defaultMetrics := types.Metrics{ | ||||
| 		Prometheus: &types.Prometheus{ | ||||
| 			Buckets:    types.Buckets{0.1, 0.3, 1.2, 5}, | ||||
| 			EntryPoint: configuration.DefaultInternalEntryPointName, | ||||
| 		}, | ||||
| 		Datadog: &types.Datadog{ | ||||
| 			Address:      "localhost:8125", | ||||
| 			PushInterval: "10s", | ||||
| 		}, | ||||
| 		StatsD: &types.Statsd{ | ||||
| 			Address:      "localhost:8125", | ||||
| 			PushInterval: "10s", | ||||
| 		}, | ||||
| 		InfluxDB: &types.InfluxDB{ | ||||
| 			Address:      "localhost:8089", | ||||
| 			PushInterval: "10s", | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	defaultConfiguration := configuration.GlobalConfiguration{ | ||||
| 		Docker:             &defaultDocker, | ||||
| 		File:               &defaultFile, | ||||
| 		Web:                &defaultWeb, | ||||
| 		Rest:               &defaultRest, | ||||
| 		Marathon:           &defaultMarathon, | ||||
| 		Consul:             &defaultConsul, | ||||
| 		ConsulCatalog:      &defaultConsulCatalog, | ||||
| 		Etcd:               &defaultEtcd, | ||||
| 		Zookeeper:          &defaultZookeeper, | ||||
| 		Boltdb:             &defaultBoltDb, | ||||
| 		Kubernetes:         &defaultKubernetes, | ||||
| 		Mesos:              &defaultMesos, | ||||
| 		ECS:                &defaultECS, | ||||
| 		Rancher:            &defaultRancher, | ||||
| 		Eureka:             &defaultEureka, | ||||
| 		DynamoDB:           &defaultDynamoDB, | ||||
| 		Retry:              &configuration.Retry{}, | ||||
| 		HealthCheck:        &healthCheck, | ||||
| 		RespondingTimeouts: &respondingTimeouts, | ||||
| 		ForwardingTimeouts: &forwardingTimeouts, | ||||
| 		TraefikLog:         &defaultTraefikLog, | ||||
| 		AccessLog:          &defaultAccessLog, | ||||
| 		LifeCycle:          &defaultLifeCycle, | ||||
| 		Ping:               &defaultPing, | ||||
| 		API:                &defaultAPI, | ||||
| 		Metrics:            &defaultMetrics, | ||||
| 		Tracing:            &defaultTracing, | ||||
| 	} | ||||
|  | ||||
| 	return &TraefikConfiguration{ | ||||
| 		GlobalConfiguration: defaultConfiguration, | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // NewTraefikConfiguration creates a TraefikConfiguration with default values | ||||
| func NewTraefikConfiguration() *TraefikConfiguration { | ||||
| 	return &TraefikConfiguration{ | ||||
| 		GlobalConfiguration: configuration.GlobalConfiguration{ | ||||
| 			AccessLogsFile:            "", | ||||
| 			TraefikLogsFile:           "", | ||||
| 			EntryPoints:               map[string]*configuration.EntryPoint{}, | ||||
| 			Constraints:               types.Constraints{}, | ||||
| 			DefaultEntryPoints:        []string{"http"}, | ||||
| 			ProvidersThrottleDuration: flaeg.Duration(2 * time.Second), | ||||
| 			MaxIdleConnsPerHost:       200, | ||||
| 			IdleTimeout:               flaeg.Duration(0), | ||||
| 			HealthCheck: &configuration.HealthCheckConfig{ | ||||
| 				Interval: flaeg.Duration(configuration.DefaultHealthCheckInterval), | ||||
| 			EntryPoints: make(static.EntryPoints), | ||||
| 			Providers: &static.Providers{ | ||||
| 				ProvidersThrottleDuration: ptypes.Duration(2 * time.Second), | ||||
| 			}, | ||||
| 			LifeCycle: &configuration.LifeCycle{ | ||||
| 				GraceTimeOut: flaeg.Duration(configuration.DefaultGraceTimeout), | ||||
| 			ServersTransport: &static.ServersTransport{ | ||||
| 				MaxIdleConnsPerHost: 200, | ||||
| 			}, | ||||
| 			TCPServersTransport: &static.TCPServersTransport{ | ||||
| 				DialTimeout:   ptypes.Duration(30 * time.Second), | ||||
| 				DialKeepAlive: ptypes.Duration(15 * time.Second), | ||||
| 			}, | ||||
| 			CheckNewVersion: true, | ||||
| 		}, | ||||
| 		ConfigFile: "", | ||||
| 	} | ||||
|   | ||||
| @@ -1,22 +0,0 @@ | ||||
| package cmd | ||||
|  | ||||
| import ( | ||||
| 	"context" | ||||
| 	"os" | ||||
| 	"os/signal" | ||||
| 	"syscall" | ||||
| ) | ||||
|  | ||||
| // ContextWithSignal create a context cancelled when SIGINT or SIGTERM are notified | ||||
| func ContextWithSignal(ctx context.Context) context.Context { | ||||
| 	newCtx, cancel := context.WithCancel(ctx) | ||||
| 	signals := make(chan os.Signal) | ||||
| 	signal.Notify(signals, syscall.SIGINT, syscall.SIGTERM) | ||||
| 	go func() { | ||||
| 		select { | ||||
| 		case <-signals: | ||||
| 			cancel() | ||||
| 		} | ||||
| 	}() | ||||
| 	return newCtx | ||||
| } | ||||
| @@ -1,41 +1,40 @@ | ||||
| package healthcheck | ||||
|  | ||||
| import ( | ||||
| 	"crypto/tls" | ||||
| 	"errors" | ||||
| 	"fmt" | ||||
| 	"net/http" | ||||
| 	"os" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/containous/flaeg" | ||||
| 	"github.com/containous/traefik/cmd" | ||||
| 	"github.com/containous/traefik/configuration" | ||||
| 	"github.com/traefik/paerser/cli" | ||||
| 	"github.com/traefik/traefik/v3/pkg/config/static" | ||||
| ) | ||||
|  | ||||
| // NewCmd builds a new HealthCheck command | ||||
| func NewCmd(traefikConfiguration *cmd.TraefikConfiguration, traefikPointersConfiguration *cmd.TraefikConfiguration) *flaeg.Command { | ||||
| 	return &flaeg.Command{ | ||||
| 		Name:                  "healthcheck", | ||||
| 		Description:           `Calls traefik /ping to check health (web provider must be enabled)`, | ||||
| 		Config:                traefikConfiguration, | ||||
| 		DefaultPointersConfig: traefikPointersConfiguration, | ||||
| 		Run: runCmd(traefikConfiguration), | ||||
| 		Metadata: map[string]string{ | ||||
| 			"parseAllSources": "true", | ||||
| 		}, | ||||
| // NewCmd builds a new HealthCheck command. | ||||
| func NewCmd(traefikConfiguration *static.Configuration, loaders []cli.ResourceLoader) *cli.Command { | ||||
| 	return &cli.Command{ | ||||
| 		Name:          "healthcheck", | ||||
| 		Description:   `Calls Traefik /ping endpoint (disabled by default) to check the health of Traefik.`, | ||||
| 		Configuration: traefikConfiguration, | ||||
| 		Run:           runCmd(traefikConfiguration), | ||||
| 		Resources:     loaders, | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func runCmd(traefikConfiguration *cmd.TraefikConfiguration) func() error { | ||||
| 	return func() error { | ||||
| 		traefikConfiguration.GlobalConfiguration.SetEffectiveConfiguration(traefikConfiguration.ConfigFile) | ||||
| func runCmd(traefikConfiguration *static.Configuration) func(_ []string) error { | ||||
| 	return func(_ []string) error { | ||||
| 		traefikConfiguration.SetEffectiveConfiguration() | ||||
|  | ||||
| 		resp, errPing := Do(traefikConfiguration.GlobalConfiguration) | ||||
| 		resp, errPing := Do(*traefikConfiguration) | ||||
| 		if resp != nil { | ||||
| 			resp.Body.Close() | ||||
| 		} | ||||
| 		if errPing != nil { | ||||
| 			fmt.Printf("Error calling healthcheck: %s\n", errPing) | ||||
| 			os.Exit(1) | ||||
| 		} | ||||
|  | ||||
| 		if resp.StatusCode != http.StatusOK { | ||||
| 			fmt.Printf("Bad healthcheck status: %s\n", resp.Status) | ||||
| 			os.Exit(1) | ||||
| @@ -46,28 +45,35 @@ func runCmd(traefikConfiguration *cmd.TraefikConfiguration) func() error { | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // Do try to do a healthcheck | ||||
| func Do(globalConfiguration configuration.GlobalConfiguration) (*http.Response, error) { | ||||
| 	if globalConfiguration.Ping == nil { | ||||
| // Do try to do a healthcheck. | ||||
| func Do(staticConfiguration static.Configuration) (*http.Response, error) { | ||||
| 	if staticConfiguration.Ping == nil { | ||||
| 		return nil, errors.New("please enable `ping` to use health check") | ||||
| 	} | ||||
| 	pingEntryPoint, ok := globalConfiguration.EntryPoints[globalConfiguration.Ping.EntryPoint] | ||||
|  | ||||
| 	ep := staticConfiguration.Ping.EntryPoint | ||||
| 	if ep == "" { | ||||
| 		ep = "traefik" | ||||
| 	} | ||||
|  | ||||
| 	pingEntryPoint, ok := staticConfiguration.EntryPoints[ep] | ||||
| 	if !ok { | ||||
| 		return nil, errors.New("missing `ping` entrypoint") | ||||
| 		return nil, fmt.Errorf("ping: missing %s entry point", ep) | ||||
| 	} | ||||
|  | ||||
| 	client := &http.Client{Timeout: 5 * time.Second} | ||||
| 	protocol := "http" | ||||
| 	if pingEntryPoint.TLS != nil { | ||||
| 		protocol = "https" | ||||
| 		tr := &http.Transport{ | ||||
| 			TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, | ||||
| 		} | ||||
| 		client.Transport = tr | ||||
| 	} | ||||
|  | ||||
| 	// TODO Handle TLS on ping etc... | ||||
| 	// if pingEntryPoint.TLS != nil { | ||||
| 	// 	protocol = "https" | ||||
| 	// 	tr := &http.Transport{ | ||||
| 	// 		TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, | ||||
| 	// 	} | ||||
| 	// 	client.Transport = tr | ||||
| 	// } | ||||
|  | ||||
| 	path := "/" | ||||
| 	if globalConfiguration.Web != nil { | ||||
| 		path = globalConfiguration.Web.Path | ||||
| 	} | ||||
| 	return client.Head(protocol + "://" + pingEntryPoint.Address + path + "ping") | ||||
|  | ||||
| 	return client.Head(protocol + "://" + pingEntryPoint.GetAddress() + path + "ping") | ||||
| } | ||||
|   | ||||
							
								
								
									
										332
									
								
								cmd/internal/gen/centrifuge.go
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										332
									
								
								cmd/internal/gen/centrifuge.go
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,332 @@ | ||||
| package main | ||||
|  | ||||
| import ( | ||||
| 	"bytes" | ||||
| 	"fmt" | ||||
| 	"go/format" | ||||
| 	"go/importer" | ||||
| 	"go/token" | ||||
| 	"go/types" | ||||
| 	"io" | ||||
| 	"log" | ||||
| 	"os" | ||||
| 	"path" | ||||
| 	"path/filepath" | ||||
| 	"reflect" | ||||
| 	"slices" | ||||
| 	"sort" | ||||
| 	"strings" | ||||
|  | ||||
| 	"golang.org/x/tools/imports" | ||||
| ) | ||||
|  | ||||
| // File a kind of AST element that represents a file. | ||||
| type File struct { | ||||
| 	Package  string | ||||
| 	Imports  []string | ||||
| 	Elements []Element | ||||
| } | ||||
|  | ||||
| // Element is a simplified version of a symbol. | ||||
| type Element struct { | ||||
| 	Name  string | ||||
| 	Value string | ||||
| } | ||||
|  | ||||
| // Centrifuge a centrifuge. | ||||
| // Generate Go Structures from Go structures. | ||||
| type Centrifuge struct { | ||||
| 	IncludedImports []string | ||||
| 	ExcludedTypes   []string | ||||
| 	ExcludedFiles   []string | ||||
|  | ||||
| 	TypeCleaner    func(types.Type, string) string | ||||
| 	PackageCleaner func(string) string | ||||
|  | ||||
| 	rootPkg string | ||||
| 	fileSet *token.FileSet | ||||
| 	pkg     *types.Package | ||||
| } | ||||
|  | ||||
| // NewCentrifuge creates a new Centrifuge. | ||||
| func NewCentrifuge(rootPkg string) (*Centrifuge, error) { | ||||
| 	fileSet := token.NewFileSet() | ||||
|  | ||||
| 	pkg, err := importer.ForCompiler(fileSet, "source", nil).Import(rootPkg) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	return &Centrifuge{ | ||||
| 		fileSet: fileSet, | ||||
| 		pkg:     pkg, | ||||
| 		rootPkg: rootPkg, | ||||
|  | ||||
| 		TypeCleaner: func(typ types.Type, _ string) string { | ||||
| 			return typ.String() | ||||
| 		}, | ||||
| 		PackageCleaner: func(s string) string { | ||||
| 			return s | ||||
| 		}, | ||||
| 	}, nil | ||||
| } | ||||
|  | ||||
| // Run runs the code extraction and the code generation. | ||||
| func (c Centrifuge) Run(dest string, pkgName string) error { | ||||
| 	files := c.run(c.pkg.Scope(), c.rootPkg, pkgName) | ||||
|  | ||||
| 	err := fileWriter{baseDir: dest}.Write(files) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	for _, p := range c.pkg.Imports() { | ||||
| 		if slices.Contains(c.IncludedImports, p.Path()) { | ||||
| 			fls := c.run(p.Scope(), p.Path(), p.Name()) | ||||
|  | ||||
| 			err = fileWriter{baseDir: filepath.Join(dest, p.Name())}.Write(fls) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return err | ||||
| } | ||||
|  | ||||
| func (c Centrifuge) run(sc *types.Scope, rootPkg string, pkgName string) map[string]*File { | ||||
| 	files := map[string]*File{} | ||||
|  | ||||
| 	for _, name := range sc.Names() { | ||||
| 		if slices.Contains(c.ExcludedTypes, name) { | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		o := sc.Lookup(name) | ||||
| 		if !o.Exported() { | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		filename := filepath.Base(c.fileSet.File(o.Pos()).Name()) | ||||
| 		if slices.Contains(c.ExcludedFiles, path.Join(rootPkg, filename)) { | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		fl, ok := files[filename] | ||||
| 		if !ok { | ||||
| 			files[filename] = &File{Package: pkgName} | ||||
| 			fl = files[filename] | ||||
| 		} | ||||
|  | ||||
| 		elt := Element{ | ||||
| 			Name: name, | ||||
| 		} | ||||
|  | ||||
| 		switch ob := o.(type) { | ||||
| 		case *types.TypeName: | ||||
|  | ||||
| 			switch obj := ob.Type().(*types.Named).Underlying().(type) { | ||||
| 			case *types.Struct: | ||||
| 				elt.Value = c.writeStruct(name, obj, rootPkg, fl) | ||||
|  | ||||
| 			case *types.Map: | ||||
| 				elt.Value = fmt.Sprintf("type %s map[%s]%s\n", name, obj.Key().String(), c.TypeCleaner(obj.Elem(), rootPkg)) | ||||
|  | ||||
| 			case *types.Slice: | ||||
| 				elt.Value = fmt.Sprintf("type %s []%v\n", name, c.TypeCleaner(obj.Elem(), rootPkg)) | ||||
|  | ||||
| 			case *types.Basic: | ||||
| 				elt.Value = fmt.Sprintf("type %s %v\n", name, obj.Name()) | ||||
|  | ||||
| 			default: | ||||
| 				log.Printf("OTHER TYPE::: %s %T\n", name, o.Type().(*types.Named).Underlying()) | ||||
| 				continue | ||||
| 			} | ||||
|  | ||||
| 		default: | ||||
| 			log.Printf("OTHER::: %s %T\n", name, o) | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		if len(elt.Value) > 0 { | ||||
| 			fl.Elements = append(fl.Elements, elt) | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return files | ||||
| } | ||||
|  | ||||
| func (c Centrifuge) writeStruct(name string, obj *types.Struct, rootPkg string, elt *File) string { | ||||
| 	b := strings.Builder{} | ||||
| 	b.WriteString(fmt.Sprintf("type %s struct {\n", name)) | ||||
|  | ||||
| 	for i := range obj.NumFields() { | ||||
| 		field := obj.Field(i) | ||||
|  | ||||
| 		if !field.Exported() { | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		fPkg := c.PackageCleaner(extractPackage(field.Type())) | ||||
| 		if fPkg != "" && fPkg != rootPkg { | ||||
| 			elt.Imports = append(elt.Imports, fPkg) | ||||
| 		} | ||||
|  | ||||
| 		fType := c.TypeCleaner(field.Type(), rootPkg) | ||||
|  | ||||
| 		if field.Embedded() { | ||||
| 			b.WriteString(fmt.Sprintf("\t%s\n", fType)) | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		values, ok := lookupTagValue(obj.Tag(i), "json") | ||||
| 		if len(values) > 0 && values[0] == "-" { | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		b.WriteString(fmt.Sprintf("\t%s %s", field.Name(), fType)) | ||||
|  | ||||
| 		if ok { | ||||
| 			b.WriteString(fmt.Sprintf(" `json:\"%s\"`", strings.Join(values, ","))) | ||||
| 		} | ||||
|  | ||||
| 		b.WriteString("\n") | ||||
| 	} | ||||
|  | ||||
| 	b.WriteString("}\n") | ||||
|  | ||||
| 	return b.String() | ||||
| } | ||||
|  | ||||
| func lookupTagValue(raw, key string) ([]string, bool) { | ||||
| 	value, ok := reflect.StructTag(raw).Lookup(key) | ||||
| 	if !ok { | ||||
| 		return nil, ok | ||||
| 	} | ||||
|  | ||||
| 	values := strings.Split(value, ",") | ||||
|  | ||||
| 	if len(values) < 1 { | ||||
| 		return nil, true | ||||
| 	} | ||||
|  | ||||
| 	return values, true | ||||
| } | ||||
|  | ||||
| func extractPackage(t types.Type) string { | ||||
| 	switch tu := t.(type) { | ||||
| 	case *types.Named: | ||||
| 		return tu.Obj().Pkg().Path() | ||||
|  | ||||
| 	case *types.Slice: | ||||
| 		if v, ok := tu.Elem().(*types.Named); ok { | ||||
| 			return v.Obj().Pkg().Path() | ||||
| 		} | ||||
| 		return "" | ||||
|  | ||||
| 	case *types.Map: | ||||
| 		if v, ok := tu.Elem().(*types.Named); ok { | ||||
| 			return v.Obj().Pkg().Path() | ||||
| 		} | ||||
| 		return "" | ||||
|  | ||||
| 	case *types.Pointer: | ||||
| 		return extractPackage(tu.Elem()) | ||||
|  | ||||
| 	default: | ||||
| 		return "" | ||||
| 	} | ||||
| } | ||||
|  | ||||
| type fileWriter struct { | ||||
| 	baseDir string | ||||
| } | ||||
|  | ||||
| func (f fileWriter) Write(files map[string]*File) error { | ||||
| 	err := os.MkdirAll(f.baseDir, 0o755) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	for name, file := range files { | ||||
| 		err = f.writeFile(name, file) | ||||
| 		if err != nil { | ||||
| 			return err | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func (f fileWriter) writeFile(name string, desc *File) error { | ||||
| 	if len(desc.Elements) == 0 { | ||||
| 		return nil | ||||
| 	} | ||||
|  | ||||
| 	filename := filepath.Join(f.baseDir, name) | ||||
|  | ||||
| 	file, err := os.Create(filename) | ||||
| 	if err != nil { | ||||
| 		return fmt.Errorf("failed to create file: %w", err) | ||||
| 	} | ||||
|  | ||||
| 	defer func() { _ = file.Close() }() | ||||
|  | ||||
| 	b := bytes.NewBufferString("package ") | ||||
| 	b.WriteString(desc.Package) | ||||
| 	b.WriteString("\n") | ||||
| 	b.WriteString("// Code generated by centrifuge. DO NOT EDIT.\n") | ||||
|  | ||||
| 	b.WriteString("\n") | ||||
| 	f.writeImports(b, desc.Imports) | ||||
| 	b.WriteString("\n") | ||||
|  | ||||
| 	for _, elt := range desc.Elements { | ||||
| 		b.WriteString(elt.Value) | ||||
| 		b.WriteString("\n") | ||||
| 	} | ||||
|  | ||||
| 	// gofmt | ||||
| 	source, err := format.Source(b.Bytes()) | ||||
| 	if err != nil { | ||||
| 		log.Println(b.String()) | ||||
| 		return fmt.Errorf("failed to format sources: %w", err) | ||||
| 	} | ||||
|  | ||||
| 	// goimports | ||||
| 	process, err := imports.Process(filename, source, nil) | ||||
| 	if err != nil { | ||||
| 		log.Println(string(source)) | ||||
| 		return fmt.Errorf("failed to format imports: %w", err) | ||||
| 	} | ||||
|  | ||||
| 	_, err = file.Write(process) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func (f fileWriter) writeImports(b io.StringWriter, imports []string) { | ||||
| 	if len(imports) == 0 { | ||||
| 		return | ||||
| 	} | ||||
|  | ||||
| 	uniq := map[string]struct{}{} | ||||
|  | ||||
| 	sort.Strings(imports) | ||||
|  | ||||
| 	_, _ = b.WriteString("import (\n") | ||||
| 	for _, s := range imports { | ||||
| 		if _, exist := uniq[s]; exist { | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		uniq[s] = struct{}{} | ||||
|  | ||||
| 		_, _ = b.WriteString(fmt.Sprintf(`	"%s"`+"\n", s)) | ||||
| 	} | ||||
|  | ||||
| 	_, _ = b.WriteString(")\n") | ||||
| } | ||||
							
								
								
									
										124
									
								
								cmd/internal/gen/main.go
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										124
									
								
								cmd/internal/gen/main.go
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,124 @@ | ||||
| package main | ||||
|  | ||||
| import ( | ||||
| 	"fmt" | ||||
| 	"go/build" | ||||
| 	"go/types" | ||||
| 	"log" | ||||
| 	"os" | ||||
| 	"path" | ||||
| 	"path/filepath" | ||||
| 	"strings" | ||||
| ) | ||||
|  | ||||
| const rootPkg = "github.com/traefik/traefik/v3/pkg/config/dynamic" | ||||
|  | ||||
| const ( | ||||
| 	destModuleName = "github.com/traefik/genconf" | ||||
| 	destPkg        = "dynamic" | ||||
| ) | ||||
|  | ||||
| const marsh = `package %s | ||||
|  | ||||
| import "encoding/json" | ||||
|  | ||||
| type JSONPayload struct { | ||||
| 	*Configuration | ||||
| } | ||||
|  | ||||
| func (c JSONPayload) MarshalJSON() ([]byte, error) { | ||||
| 	if c.Configuration == nil { | ||||
| 		return nil, nil | ||||
| 	} | ||||
|  | ||||
| 	return json.Marshal(c.Configuration) | ||||
| } | ||||
| ` | ||||
|  | ||||
| // main generate Go Structures from Go structures. | ||||
| // Allows to create an external module (destModuleName) used by the plugin's providers | ||||
| // that contains Go structs of the dynamic configuration and nothing else. | ||||
| // These Go structs do not have any non-exported fields and do not rely on any external dependencies. | ||||
| func main() { | ||||
| 	dest := filepath.Join(path.Join(build.Default.GOPATH, "src"), destModuleName, destPkg) | ||||
|  | ||||
| 	log.Println("Output:", dest) | ||||
|  | ||||
| 	err := run(dest) | ||||
| 	if err != nil { | ||||
| 		log.Fatal(err) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func run(dest string) error { | ||||
| 	centrifuge, err := NewCentrifuge(rootPkg) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	centrifuge.IncludedImports = []string{ | ||||
| 		"github.com/traefik/traefik/v3/pkg/tls", | ||||
| 		"github.com/traefik/traefik/v3/pkg/types", | ||||
| 	} | ||||
|  | ||||
| 	centrifuge.ExcludedTypes = []string{ | ||||
| 		// tls | ||||
| 		"CertificateStore", "Manager", | ||||
| 		// dynamic | ||||
| 		"Message", "Configurations", | ||||
| 		// types | ||||
| 		"HTTPCodeRanges", "HostResolverConfig", | ||||
| 	} | ||||
|  | ||||
| 	centrifuge.ExcludedFiles = []string{ | ||||
| 		"github.com/traefik/traefik/v3/pkg/types/logs.go", | ||||
| 		"github.com/traefik/traefik/v3/pkg/types/metrics.go", | ||||
| 	} | ||||
|  | ||||
| 	centrifuge.TypeCleaner = cleanType | ||||
| 	centrifuge.PackageCleaner = cleanPackage | ||||
|  | ||||
| 	err = centrifuge.Run(dest, destPkg) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	return os.WriteFile(filepath.Join(dest, "marshaler.go"), []byte(fmt.Sprintf(marsh, destPkg)), 0o666) | ||||
| } | ||||
|  | ||||
| func cleanType(typ types.Type, base string) string { | ||||
| 	if typ.String() == "github.com/traefik/traefik/v3/pkg/types.FileOrContent" { | ||||
| 		return "string" | ||||
| 	} | ||||
|  | ||||
| 	if typ.String() == "[]github.com/traefik/traefik/v3/pkg/types.FileOrContent" { | ||||
| 		return "[]string" | ||||
| 	} | ||||
|  | ||||
| 	if typ.String() == "github.com/traefik/paerser/types.Duration" { | ||||
| 		return "string" | ||||
| 	} | ||||
|  | ||||
| 	if strings.Contains(typ.String(), base) { | ||||
| 		return strings.ReplaceAll(typ.String(), base+".", "") | ||||
| 	} | ||||
|  | ||||
| 	if strings.Contains(typ.String(), "github.com/traefik/traefik/v3/pkg/") { | ||||
| 		return strings.ReplaceAll(typ.String(), "github.com/traefik/traefik/v3/pkg/", "") | ||||
| 	} | ||||
|  | ||||
| 	return typ.String() | ||||
| } | ||||
|  | ||||
| func cleanPackage(src string) string { | ||||
| 	switch src { | ||||
| 	case "github.com/traefik/paerser/types": | ||||
| 		return "" | ||||
| 	case "github.com/traefik/traefik/v3/pkg/tls": | ||||
| 		return path.Join(destModuleName, destPkg, "tls") | ||||
| 	case "github.com/traefik/traefik/v3/pkg/types": | ||||
| 		return path.Join(destModuleName, destPkg, "types") | ||||
| 	default: | ||||
| 		return src | ||||
| 	} | ||||
| } | ||||
| @@ -1,186 +0,0 @@ | ||||
| package storeconfig | ||||
|  | ||||
| import ( | ||||
| 	"encoding/json" | ||||
| 	"fmt" | ||||
| 	"io/ioutil" | ||||
| 	stdlog "log" | ||||
| 	"os" | ||||
|  | ||||
| 	"github.com/abronan/valkeyrie/store" | ||||
| 	"github.com/containous/flaeg" | ||||
| 	"github.com/containous/staert" | ||||
| 	"github.com/containous/traefik/acme" | ||||
| 	"github.com/containous/traefik/cluster" | ||||
| 	"github.com/containous/traefik/cmd" | ||||
| 	"github.com/containous/traefik/log" | ||||
| ) | ||||
|  | ||||
| // NewCmd builds a new StoreConfig command | ||||
| func NewCmd(traefikConfiguration *cmd.TraefikConfiguration, traefikPointersConfiguration *cmd.TraefikConfiguration) *flaeg.Command { | ||||
| 	return &flaeg.Command{ | ||||
| 		Name:                  "storeconfig", | ||||
| 		Description:           `Store the static traefik configuration into a Key-value stores. Traefik will not start.`, | ||||
| 		Config:                traefikConfiguration, | ||||
| 		DefaultPointersConfig: traefikPointersConfiguration, | ||||
| 		Metadata: map[string]string{ | ||||
| 			"parseAllSources": "true", | ||||
| 		}, | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // Run store config in KV | ||||
| func Run(kv *staert.KvSource, traefikConfiguration *cmd.TraefikConfiguration) func() error { | ||||
| 	return func() error { | ||||
| 		if kv == nil { | ||||
| 			return fmt.Errorf("error using command storeconfig, no Key-value store defined") | ||||
| 		} | ||||
|  | ||||
| 		fileConfig := traefikConfiguration.GlobalConfiguration.File | ||||
| 		if fileConfig != nil { | ||||
| 			traefikConfiguration.GlobalConfiguration.File = nil | ||||
| 			if len(fileConfig.Filename) == 0 && len(fileConfig.Directory) == 0 { | ||||
| 				fileConfig.Filename = traefikConfiguration.ConfigFile | ||||
| 			} | ||||
| 		} | ||||
|  | ||||
| 		jsonConf, err := json.Marshal(traefikConfiguration.GlobalConfiguration) | ||||
| 		if err != nil { | ||||
| 			return err | ||||
| 		} | ||||
| 		stdlog.Printf("Storing configuration: %s\n", jsonConf) | ||||
|  | ||||
| 		err = kv.StoreConfig(traefikConfiguration.GlobalConfiguration) | ||||
| 		if err != nil { | ||||
| 			return err | ||||
| 		} | ||||
|  | ||||
| 		if fileConfig != nil { | ||||
| 			jsonConf, err = json.Marshal(fileConfig) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
|  | ||||
| 			stdlog.Printf("Storing file configuration: %s\n", jsonConf) | ||||
| 			config, err := fileConfig.BuildConfiguration() | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
|  | ||||
| 			stdlog.Print("Writing config to KV") | ||||
| 			err = kv.StoreConfig(config) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
| 		} | ||||
|  | ||||
| 		if traefikConfiguration.GlobalConfiguration.ACME != nil { | ||||
| 			account := &acme.Account{} | ||||
|  | ||||
| 			// Migrate ACME data from file to KV store if needed | ||||
| 			if len(traefikConfiguration.GlobalConfiguration.ACME.StorageFile) > 0 { | ||||
| 				account, err = migrateACMEData(traefikConfiguration.GlobalConfiguration.ACME.StorageFile) | ||||
| 				if err != nil { | ||||
| 					return err | ||||
| 				} | ||||
| 			} | ||||
|  | ||||
| 			// Store the ACME Account into the KV Store | ||||
| 			meta := cluster.NewMetadata(account) | ||||
| 			err = meta.Marshall() | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
|  | ||||
| 			source := staert.KvSource{ | ||||
| 				Store:  kv, | ||||
| 				Prefix: traefikConfiguration.GlobalConfiguration.ACME.Storage, | ||||
| 			} | ||||
|  | ||||
| 			err = source.StoreConfig(meta) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} | ||||
|  | ||||
| 			// Force to delete storagefile | ||||
| 			return kv.Delete(kv.Prefix + "/acme/storagefile") | ||||
| 		} | ||||
| 		return nil | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // migrateACMEData allows migrating data from acme.json file to KV store in function of the file format | ||||
| func migrateACMEData(fileName string) (*acme.Account, error) { | ||||
|  | ||||
| 	f, err := os.Open(fileName) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	defer f.Close() | ||||
|  | ||||
| 	file, err := ioutil.ReadAll(f) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	// Check if the storage file is not empty before to get data | ||||
| 	account := &acme.Account{} | ||||
| 	if len(file) > 0 { | ||||
| 		accountFromNewFormat, err := acme.FromNewToOldFormat(fileName) | ||||
| 		if err != nil { | ||||
| 			return nil, err | ||||
| 		} | ||||
|  | ||||
| 		if accountFromNewFormat == nil { | ||||
| 			// convert ACME json file to KV store (used for backward compatibility) | ||||
| 			localStore := acme.NewLocalStore(fileName) | ||||
| 			account, err = localStore.Get() | ||||
| 			if err != nil { | ||||
| 				return nil, err | ||||
| 			} | ||||
| 		} else { | ||||
| 			account = accountFromNewFormat | ||||
| 		} | ||||
| 	} else { | ||||
| 		log.Warnf("No data will be imported from the storageFile %q because it is empty.", fileName) | ||||
| 	} | ||||
|  | ||||
| 	err = account.Init() | ||||
| 	return account, err | ||||
| } | ||||
|  | ||||
| // CreateKvSource creates KvSource | ||||
| // TLS support is enable for Consul and Etcd backends | ||||
| func CreateKvSource(traefikConfiguration *cmd.TraefikConfiguration) (*staert.KvSource, error) { | ||||
| 	var kv *staert.KvSource | ||||
| 	var kvStore store.Store | ||||
| 	var err error | ||||
|  | ||||
| 	switch { | ||||
| 	case traefikConfiguration.Consul != nil: | ||||
| 		kvStore, err = traefikConfiguration.Consul.CreateStore() | ||||
| 		kv = &staert.KvSource{ | ||||
| 			Store:  kvStore, | ||||
| 			Prefix: traefikConfiguration.Consul.Prefix, | ||||
| 		} | ||||
| 	case traefikConfiguration.Etcd != nil: | ||||
| 		kvStore, err = traefikConfiguration.Etcd.CreateStore() | ||||
| 		kv = &staert.KvSource{ | ||||
| 			Store:  kvStore, | ||||
| 			Prefix: traefikConfiguration.Etcd.Prefix, | ||||
| 		} | ||||
| 	case traefikConfiguration.Zookeeper != nil: | ||||
| 		kvStore, err = traefikConfiguration.Zookeeper.CreateStore() | ||||
| 		kv = &staert.KvSource{ | ||||
| 			Store:  kvStore, | ||||
| 			Prefix: traefikConfiguration.Zookeeper.Prefix, | ||||
| 		} | ||||
| 	case traefikConfiguration.Boltdb != nil: | ||||
| 		kvStore, err = traefikConfiguration.Boltdb.CreateStore() | ||||
| 		kv = &staert.KvSource{ | ||||
| 			Store:  kvStore, | ||||
| 			Prefix: traefikConfiguration.Boltdb.Prefix, | ||||
| 		} | ||||
| 	} | ||||
| 	return kv, err | ||||
| } | ||||
							
								
								
									
										89
									
								
								cmd/traefik/logger.go
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										89
									
								
								cmd/traefik/logger.go
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,89 @@ | ||||
| package main | ||||
|  | ||||
| import ( | ||||
| 	"io" | ||||
| 	stdlog "log" | ||||
| 	"os" | ||||
| 	"strings" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/rs/zerolog" | ||||
| 	"github.com/rs/zerolog/log" | ||||
| 	"github.com/sirupsen/logrus" | ||||
| 	"github.com/traefik/traefik/v3/pkg/config/static" | ||||
| 	"github.com/traefik/traefik/v3/pkg/logs" | ||||
| 	"gopkg.in/natefinch/lumberjack.v2" | ||||
| ) | ||||
|  | ||||
| func init() { | ||||
| 	// hide the first logs before the setup of the logger. | ||||
| 	zerolog.SetGlobalLevel(zerolog.ErrorLevel) | ||||
| } | ||||
|  | ||||
| func setupLogger(staticConfiguration *static.Configuration) { | ||||
| 	// configure log format | ||||
| 	w := getLogWriter(staticConfiguration) | ||||
|  | ||||
| 	// configure log level | ||||
| 	logLevel := getLogLevel(staticConfiguration) | ||||
|  | ||||
| 	// create logger | ||||
| 	logCtx := zerolog.New(w).With().Timestamp() | ||||
| 	if logLevel <= zerolog.DebugLevel { | ||||
| 		logCtx = logCtx.Caller() | ||||
| 	} | ||||
|  | ||||
| 	log.Logger = logCtx.Logger().Level(logLevel) | ||||
| 	zerolog.DefaultContextLogger = &log.Logger | ||||
| 	zerolog.SetGlobalLevel(logLevel) | ||||
|  | ||||
| 	// Global logrus replacement (related to lib like go-rancher-metadata, docker, etc.) | ||||
| 	logrus.StandardLogger().Out = logs.NoLevel(log.Logger, zerolog.DebugLevel) | ||||
|  | ||||
| 	// configure default standard log. | ||||
| 	stdlog.SetFlags(stdlog.Lshortfile | stdlog.LstdFlags) | ||||
| 	stdlog.SetOutput(logs.NoLevel(log.Logger, zerolog.DebugLevel)) | ||||
| } | ||||
|  | ||||
| func getLogWriter(staticConfiguration *static.Configuration) io.Writer { | ||||
| 	var w io.Writer = os.Stderr | ||||
|  | ||||
| 	if staticConfiguration.Log != nil && len(staticConfiguration.Log.FilePath) > 0 { | ||||
| 		_, _ = os.OpenFile(staticConfiguration.Log.FilePath, os.O_RDWR|os.O_CREATE|os.O_APPEND, 0o666) | ||||
| 		w = &lumberjack.Logger{ | ||||
| 			Filename:   staticConfiguration.Log.FilePath, | ||||
| 			MaxSize:    staticConfiguration.Log.MaxSize, | ||||
| 			MaxBackups: staticConfiguration.Log.MaxBackups, | ||||
| 			MaxAge:     staticConfiguration.Log.MaxAge, | ||||
| 			Compress:   true, | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if staticConfiguration.Log == nil || staticConfiguration.Log.Format != "json" { | ||||
| 		w = zerolog.ConsoleWriter{ | ||||
| 			Out:        w, | ||||
| 			TimeFormat: time.RFC3339, | ||||
| 			NoColor:    staticConfiguration.Log != nil && (staticConfiguration.Log.NoColor || len(staticConfiguration.Log.FilePath) > 0), | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return w | ||||
| } | ||||
|  | ||||
| func getLogLevel(staticConfiguration *static.Configuration) zerolog.Level { | ||||
| 	levelStr := "error" | ||||
| 	if staticConfiguration.Log != nil && staticConfiguration.Log.Level != "" { | ||||
| 		levelStr = strings.ToLower(staticConfiguration.Log.Level) | ||||
| 	} | ||||
|  | ||||
| 	logLevel, err := zerolog.ParseLevel(strings.ToLower(levelStr)) | ||||
| 	if err != nil { | ||||
| 		log.Error().Err(err). | ||||
| 			Str("logLevel", levelStr). | ||||
| 			Msg("Unspecified or invalid log level, setting the level to default (ERROR)...") | ||||
|  | ||||
| 		logLevel = zerolog.ErrorLevel | ||||
| 	} | ||||
|  | ||||
| 	return logLevel | ||||
| } | ||||
							
								
								
									
										83
									
								
								cmd/traefik/plugins.go
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										83
									
								
								cmd/traefik/plugins.go
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,83 @@ | ||||
| package main | ||||
|  | ||||
| import ( | ||||
| 	"fmt" | ||||
|  | ||||
| 	"github.com/traefik/traefik/v3/pkg/config/static" | ||||
| 	"github.com/traefik/traefik/v3/pkg/plugins" | ||||
| ) | ||||
|  | ||||
| const outputDir = "./plugins-storage/" | ||||
|  | ||||
| func createPluginBuilder(staticConfiguration *static.Configuration) (*plugins.Builder, error) { | ||||
| 	client, plgs, localPlgs, err := initPlugins(staticConfiguration) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	return plugins.NewBuilder(client, plgs, localPlgs) | ||||
| } | ||||
|  | ||||
| func initPlugins(staticCfg *static.Configuration) (*plugins.Client, map[string]plugins.Descriptor, map[string]plugins.LocalDescriptor, error) { | ||||
| 	err := checkUniquePluginNames(staticCfg.Experimental) | ||||
| 	if err != nil { | ||||
| 		return nil, nil, nil, err | ||||
| 	} | ||||
|  | ||||
| 	var client *plugins.Client | ||||
| 	plgs := map[string]plugins.Descriptor{} | ||||
|  | ||||
| 	if hasPlugins(staticCfg) { | ||||
| 		opts := plugins.ClientOptions{ | ||||
| 			Output: outputDir, | ||||
| 		} | ||||
|  | ||||
| 		var err error | ||||
| 		client, err = plugins.NewClient(opts) | ||||
| 		if err != nil { | ||||
| 			return nil, nil, nil, fmt.Errorf("unable to create plugins client: %w", err) | ||||
| 		} | ||||
|  | ||||
| 		err = plugins.SetupRemotePlugins(client, staticCfg.Experimental.Plugins) | ||||
| 		if err != nil { | ||||
| 			return nil, nil, nil, fmt.Errorf("unable to set up plugins environment: %w", err) | ||||
| 		} | ||||
|  | ||||
| 		plgs = staticCfg.Experimental.Plugins | ||||
| 	} | ||||
|  | ||||
| 	localPlgs := map[string]plugins.LocalDescriptor{} | ||||
|  | ||||
| 	if hasLocalPlugins(staticCfg) { | ||||
| 		err := plugins.SetupLocalPlugins(staticCfg.Experimental.LocalPlugins) | ||||
| 		if err != nil { | ||||
| 			return nil, nil, nil, err | ||||
| 		} | ||||
|  | ||||
| 		localPlgs = staticCfg.Experimental.LocalPlugins | ||||
| 	} | ||||
|  | ||||
| 	return client, plgs, localPlgs, nil | ||||
| } | ||||
|  | ||||
| func checkUniquePluginNames(e *static.Experimental) error { | ||||
| 	if e == nil { | ||||
| 		return nil | ||||
| 	} | ||||
|  | ||||
| 	for s := range e.LocalPlugins { | ||||
| 		if _, ok := e.Plugins[s]; ok { | ||||
| 			return fmt.Errorf("the plugin's name %q must be unique", s) | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func hasPlugins(staticCfg *static.Configuration) bool { | ||||
| 	return staticCfg.Experimental != nil && len(staticCfg.Experimental.Plugins) > 0 | ||||
| } | ||||
|  | ||||
| func hasLocalPlugins(staticCfg *static.Configuration) bool { | ||||
| 	return staticCfg.Experimental != nil && len(staticCfg.Experimental.LocalPlugins) > 0 | ||||
| } | ||||
| @@ -2,274 +2,597 @@ package main | ||||
|  | ||||
| import ( | ||||
| 	"context" | ||||
| 	"crypto/x509" | ||||
| 	"encoding/json" | ||||
| 	fmtlog "log" | ||||
| 	"fmt" | ||||
| 	"io" | ||||
| 	stdlog "log" | ||||
| 	"net/http" | ||||
| 	"os" | ||||
| 	"path/filepath" | ||||
| 	"reflect" | ||||
| 	"os/signal" | ||||
| 	"sort" | ||||
| 	"strings" | ||||
| 	"syscall" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/cenk/backoff" | ||||
| 	"github.com/containous/flaeg" | ||||
| 	"github.com/containous/staert" | ||||
| 	"github.com/containous/traefik/cmd" | ||||
| 	"github.com/containous/traefik/cmd/bug" | ||||
| 	"github.com/containous/traefik/cmd/healthcheck" | ||||
| 	"github.com/containous/traefik/cmd/storeconfig" | ||||
| 	cmdVersion "github.com/containous/traefik/cmd/version" | ||||
| 	"github.com/containous/traefik/collector" | ||||
| 	"github.com/containous/traefik/configuration" | ||||
| 	"github.com/containous/traefik/job" | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/provider/acme" | ||||
| 	"github.com/containous/traefik/provider/ecs" | ||||
| 	"github.com/containous/traefik/provider/kubernetes" | ||||
| 	"github.com/containous/traefik/safe" | ||||
| 	"github.com/containous/traefik/server" | ||||
| 	"github.com/containous/traefik/server/uuid" | ||||
| 	traefiktls "github.com/containous/traefik/tls" | ||||
| 	"github.com/containous/traefik/types" | ||||
| 	"github.com/containous/traefik/version" | ||||
| 	"github.com/coreos/go-systemd/daemon" | ||||
| 	"github.com/ogier/pflag" | ||||
| 	"github.com/coreos/go-systemd/v22/daemon" | ||||
| 	"github.com/go-acme/lego/v4/challenge" | ||||
| 	gokitmetrics "github.com/go-kit/kit/metrics" | ||||
| 	"github.com/rs/zerolog/log" | ||||
| 	"github.com/sirupsen/logrus" | ||||
| 	"github.com/spiffe/go-spiffe/v2/workloadapi" | ||||
| 	"github.com/traefik/paerser/cli" | ||||
| 	"github.com/traefik/traefik/v3/cmd" | ||||
| 	"github.com/traefik/traefik/v3/cmd/healthcheck" | ||||
| 	cmdVersion "github.com/traefik/traefik/v3/cmd/version" | ||||
| 	tcli "github.com/traefik/traefik/v3/pkg/cli" | ||||
| 	"github.com/traefik/traefik/v3/pkg/collector" | ||||
| 	"github.com/traefik/traefik/v3/pkg/config/dynamic" | ||||
| 	"github.com/traefik/traefik/v3/pkg/config/runtime" | ||||
| 	"github.com/traefik/traefik/v3/pkg/config/static" | ||||
| 	"github.com/traefik/traefik/v3/pkg/logs" | ||||
| 	"github.com/traefik/traefik/v3/pkg/metrics" | ||||
| 	"github.com/traefik/traefik/v3/pkg/middlewares/accesslog" | ||||
| 	"github.com/traefik/traefik/v3/pkg/provider/acme" | ||||
| 	"github.com/traefik/traefik/v3/pkg/provider/aggregator" | ||||
| 	"github.com/traefik/traefik/v3/pkg/provider/tailscale" | ||||
| 	"github.com/traefik/traefik/v3/pkg/provider/traefik" | ||||
| 	"github.com/traefik/traefik/v3/pkg/safe" | ||||
| 	"github.com/traefik/traefik/v3/pkg/server" | ||||
| 	"github.com/traefik/traefik/v3/pkg/server/middleware" | ||||
| 	"github.com/traefik/traefik/v3/pkg/server/service" | ||||
| 	"github.com/traefik/traefik/v3/pkg/tcp" | ||||
| 	traefiktls "github.com/traefik/traefik/v3/pkg/tls" | ||||
| 	"github.com/traefik/traefik/v3/pkg/tracing" | ||||
| 	"github.com/traefik/traefik/v3/pkg/types" | ||||
| 	"github.com/traefik/traefik/v3/pkg/version" | ||||
| 	"golang.org/x/exp/maps" | ||||
| ) | ||||
|  | ||||
| func main() { | ||||
| 	// traefik config inits | ||||
| 	traefikConfiguration := cmd.NewTraefikConfiguration() | ||||
| 	traefikPointersConfiguration := cmd.NewTraefikDefaultPointersConfiguration() | ||||
| 	tConfig := cmd.NewTraefikConfiguration() | ||||
|  | ||||
| 	// traefik Command init | ||||
| 	traefikCmd := &flaeg.Command{ | ||||
| 	loaders := []cli.ResourceLoader{&tcli.DeprecationLoader{}, &tcli.FileLoader{}, &tcli.FlagLoader{}, &tcli.EnvLoader{}} | ||||
|  | ||||
| 	cmdTraefik := &cli.Command{ | ||||
| 		Name: "traefik", | ||||
| 		Description: `traefik is a modern HTTP reverse proxy and load balancer made to deploy microservices with ease. | ||||
| 		Description: `Traefik is a modern HTTP reverse proxy and load balancer made to deploy microservices with ease. | ||||
| Complete documentation is available at https://traefik.io`, | ||||
| 		Config:                traefikConfiguration, | ||||
| 		DefaultPointersConfig: traefikPointersConfiguration, | ||||
| 		Run: func() error { | ||||
| 			runCmd(&traefikConfiguration.GlobalConfiguration, traefikConfiguration.ConfigFile) | ||||
| 			return nil | ||||
| 		Configuration: tConfig, | ||||
| 		Resources:     loaders, | ||||
| 		Run: func(_ []string) error { | ||||
| 			return runCmd(&tConfig.Configuration) | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	// storeconfig Command init | ||||
| 	storeConfigCmd := storeconfig.NewCmd(traefikConfiguration, traefikPointersConfiguration) | ||||
|  | ||||
| 	// init flaeg source | ||||
| 	f := flaeg.New(traefikCmd, os.Args[1:]) | ||||
| 	// add custom parsers | ||||
| 	f.AddParser(reflect.TypeOf(configuration.EntryPoints{}), &configuration.EntryPoints{}) | ||||
| 	f.AddParser(reflect.TypeOf(configuration.DefaultEntryPoints{}), &configuration.DefaultEntryPoints{}) | ||||
| 	f.AddParser(reflect.TypeOf(traefiktls.RootCAs{}), &traefiktls.RootCAs{}) | ||||
| 	f.AddParser(reflect.TypeOf(types.Constraints{}), &types.Constraints{}) | ||||
| 	f.AddParser(reflect.TypeOf(kubernetes.Namespaces{}), &kubernetes.Namespaces{}) | ||||
| 	f.AddParser(reflect.TypeOf(ecs.Clusters{}), &ecs.Clusters{}) | ||||
| 	f.AddParser(reflect.TypeOf([]types.Domain{}), &types.Domains{}) | ||||
| 	f.AddParser(reflect.TypeOf(types.Buckets{}), &types.Buckets{}) | ||||
| 	f.AddParser(reflect.TypeOf(types.StatusCodes{}), &types.StatusCodes{}) | ||||
| 	f.AddParser(reflect.TypeOf(types.FieldNames{}), &types.FieldNames{}) | ||||
| 	f.AddParser(reflect.TypeOf(types.FieldHeaderNames{}), &types.FieldHeaderNames{}) | ||||
|  | ||||
| 	// add commands | ||||
| 	f.AddCommand(cmdVersion.NewCmd()) | ||||
| 	f.AddCommand(bug.NewCmd(traefikConfiguration, traefikPointersConfiguration)) | ||||
| 	f.AddCommand(storeConfigCmd) | ||||
| 	f.AddCommand(healthcheck.NewCmd(traefikConfiguration, traefikPointersConfiguration)) | ||||
|  | ||||
| 	usedCmd, err := f.GetCommand() | ||||
| 	err := cmdTraefik.AddCommand(healthcheck.NewCmd(&tConfig.Configuration, loaders)) | ||||
| 	if err != nil { | ||||
| 		fmtlog.Println(err) | ||||
| 		stdlog.Println(err) | ||||
| 		os.Exit(1) | ||||
| 	} | ||||
|  | ||||
| 	if _, err := f.Parse(usedCmd); err != nil { | ||||
| 		if err == pflag.ErrHelp { | ||||
| 			os.Exit(0) | ||||
| 		} | ||||
| 		fmtlog.Printf("Error parsing command: %s\n", err) | ||||
| 		os.Exit(1) | ||||
| 	} | ||||
|  | ||||
| 	// staert init | ||||
| 	s := staert.NewStaert(traefikCmd) | ||||
| 	// init TOML source | ||||
| 	toml := staert.NewTomlSource("traefik", []string{traefikConfiguration.ConfigFile, "/etc/traefik/", "$HOME/.traefik/", "."}) | ||||
|  | ||||
| 	// add sources to staert | ||||
| 	s.AddSource(toml) | ||||
| 	s.AddSource(f) | ||||
| 	if _, err := s.LoadConfig(); err != nil { | ||||
| 		fmtlog.Printf("Error reading TOML config file %s : %s\n", toml.ConfigFileUsed(), err) | ||||
| 		os.Exit(1) | ||||
| 	} | ||||
|  | ||||
| 	traefikConfiguration.ConfigFile = toml.ConfigFileUsed() | ||||
|  | ||||
| 	kv, err := storeconfig.CreateKvSource(traefikConfiguration) | ||||
| 	err = cmdTraefik.AddCommand(cmdVersion.NewCmd()) | ||||
| 	if err != nil { | ||||
| 		fmtlog.Printf("Error creating kv store: %s\n", err) | ||||
| 		os.Exit(1) | ||||
| 	} | ||||
| 	storeConfigCmd.Run = storeconfig.Run(kv, traefikConfiguration) | ||||
|  | ||||
| 	// if a KV Store is enable and no sub-command called in args | ||||
| 	if kv != nil && usedCmd == traefikCmd { | ||||
| 		if traefikConfiguration.Cluster == nil { | ||||
| 			traefikConfiguration.Cluster = &types.Cluster{Node: uuid.Get()} | ||||
| 		} | ||||
| 		if traefikConfiguration.Cluster.Store == nil { | ||||
| 			traefikConfiguration.Cluster.Store = &types.Store{Prefix: kv.Prefix, Store: kv.Store} | ||||
| 		} | ||||
| 		s.AddSource(kv) | ||||
| 		operation := func() error { | ||||
| 			_, err := s.LoadConfig() | ||||
| 			return err | ||||
| 		} | ||||
| 		notify := func(err error, time time.Duration) { | ||||
| 			log.Errorf("Load config error: %+v, retrying in %s", err, time) | ||||
| 		} | ||||
| 		err := backoff.RetryNotify(safe.OperationWithRecover(operation), job.NewBackOff(backoff.NewExponentialBackOff()), notify) | ||||
| 		if err != nil { | ||||
| 			fmtlog.Printf("Error loading configuration: %s\n", err) | ||||
| 			os.Exit(1) | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if err := s.Run(); err != nil { | ||||
| 		fmtlog.Printf("Error running traefik: %s\n", err) | ||||
| 		stdlog.Println(err) | ||||
| 		os.Exit(1) | ||||
| 	} | ||||
|  | ||||
| 	os.Exit(0) | ||||
| 	err = cli.Execute(cmdTraefik) | ||||
| 	if err != nil { | ||||
| 		log.Error().Err(err).Msg("Command error") | ||||
| 		logrus.Exit(1) | ||||
| 	} | ||||
|  | ||||
| 	logrus.Exit(0) | ||||
| } | ||||
|  | ||||
| func runCmd(globalConfiguration *configuration.GlobalConfiguration, configFile string) { | ||||
| 	configureLogging(globalConfiguration) | ||||
|  | ||||
| 	if len(configFile) > 0 { | ||||
| 		log.Infof("Using TOML configuration file %s", configFile) | ||||
| 	} | ||||
| func runCmd(staticConfiguration *static.Configuration) error { | ||||
| 	setupLogger(staticConfiguration) | ||||
|  | ||||
| 	http.DefaultTransport.(*http.Transport).Proxy = http.ProxyFromEnvironment | ||||
|  | ||||
| 	globalConfiguration.SetEffectiveConfiguration(configFile) | ||||
| 	globalConfiguration.ValidateConfiguration() | ||||
| 	staticConfiguration.SetEffectiveConfiguration() | ||||
| 	if err := staticConfiguration.ValidateConfiguration(); err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	jsonConf, _ := json.Marshal(globalConfiguration) | ||||
| 	log.Infof("Traefik version %s built on %s", version.Version, version.BuildDate) | ||||
| 	log.Info().Str("version", version.Version). | ||||
| 		Msgf("Traefik version %s built on %s", version.Version, version.BuildDate) | ||||
|  | ||||
| 	if globalConfiguration.CheckNewVersion { | ||||
| 	jsonConf, err := json.Marshal(staticConfiguration) | ||||
| 	if err != nil { | ||||
| 		log.Error().Err(err).Msg("Could not marshal static configuration") | ||||
| 		log.Debug().Interface("staticConfiguration", staticConfiguration).Msg("Static configuration loaded [struct]") | ||||
| 	} else { | ||||
| 		log.Debug().RawJSON("staticConfiguration", jsonConf).Msg("Static configuration loaded [json]") | ||||
| 	} | ||||
|  | ||||
| 	if staticConfiguration.Global.CheckNewVersion { | ||||
| 		checkNewVersion() | ||||
| 	} | ||||
|  | ||||
| 	stats(globalConfiguration) | ||||
| 	stats(staticConfiguration) | ||||
|  | ||||
| 	log.Debugf("Global configuration loaded %s", string(jsonConf)) | ||||
| 	if acme.IsEnabled() { | ||||
| 		store := acme.NewLocalStore(acme.Get().Storage) | ||||
| 		acme.Get().Store = &store | ||||
| 	svr, err := setupServer(staticConfiguration) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	svr := server.NewServer(*globalConfiguration, configuration.NewProviderAggregator(globalConfiguration)) | ||||
| 	if acme.IsEnabled() && acme.Get().OnHostRule { | ||||
| 		acme.Get().SetConfigListenerChan(make(chan types.Configuration)) | ||||
| 		svr.AddListener(acme.Get().ListenConfiguration) | ||||
|  | ||||
| 	ctx, _ := signal.NotifyContext(context.Background(), syscall.SIGINT, syscall.SIGTERM) | ||||
|  | ||||
| 	if staticConfiguration.Ping != nil { | ||||
| 		staticConfiguration.Ping.WithContext(ctx) | ||||
| 	} | ||||
| 	ctx := cmd.ContextWithSignal(context.Background()) | ||||
| 	svr.StartWithContext(ctx) | ||||
|  | ||||
| 	svr.Start(ctx) | ||||
| 	defer svr.Close() | ||||
|  | ||||
| 	sent, err := daemon.SdNotify(false, "READY=1") | ||||
| 	if !sent && err != nil { | ||||
| 		log.Error("Fail to notify", err) | ||||
| 		log.Error().Err(err).Msg("Failed to notify") | ||||
| 	} | ||||
|  | ||||
| 	t, err := daemon.SdWatchdogEnabled(false) | ||||
| 	if err != nil { | ||||
| 		log.Error("Problem with watchdog", err) | ||||
| 		log.Error().Err(err).Msg("Could not enable Watchdog") | ||||
| 	} else if t != 0 { | ||||
| 		// Send a ping each half time given | ||||
| 		t = t / 2 | ||||
| 		log.Info("Watchdog activated with timer each ", t) | ||||
| 		t /= 2 | ||||
| 		log.Info().Msgf("Watchdog activated with timer duration %s", t) | ||||
| 		safe.Go(func() { | ||||
| 			tick := time.Tick(t) | ||||
| 			for range tick { | ||||
| 				_, errHealthCheck := healthcheck.Do(*globalConfiguration) | ||||
| 				if globalConfiguration.Ping == nil || errHealthCheck == nil { | ||||
| 				resp, errHealthCheck := healthcheck.Do(*staticConfiguration) | ||||
| 				if resp != nil { | ||||
| 					_ = resp.Body.Close() | ||||
| 				} | ||||
|  | ||||
| 				if staticConfiguration.Ping == nil || errHealthCheck == nil { | ||||
| 					if ok, _ := daemon.SdNotify(false, "WATCHDOG=1"); !ok { | ||||
| 						log.Error("Fail to tick watchdog") | ||||
| 						log.Error().Msg("Fail to tick watchdog") | ||||
| 					} | ||||
| 				} else { | ||||
| 					log.Error(errHealthCheck) | ||||
| 					log.Error().Err(errHealthCheck).Send() | ||||
| 				} | ||||
| 			} | ||||
| 		}) | ||||
| 	} | ||||
|  | ||||
| 	svr.Wait() | ||||
| 	log.Info("Shutting down") | ||||
| 	logrus.Exit(0) | ||||
| 	log.Info().Msg("Shutting down") | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func configureLogging(globalConfiguration *configuration.GlobalConfiguration) { | ||||
| 	// configure default log flags | ||||
| 	fmtlog.SetFlags(fmtlog.Lshortfile | fmtlog.LstdFlags) | ||||
| func setupServer(staticConfiguration *static.Configuration) (*server.Server, error) { | ||||
| 	providerAggregator := aggregator.NewProviderAggregator(*staticConfiguration.Providers) | ||||
|  | ||||
| 	// configure log level | ||||
| 	// an explicitly defined log level always has precedence. if none is | ||||
| 	// given and debug mode is disabled, the default is ERROR, and DEBUG | ||||
| 	// otherwise. | ||||
| 	levelStr := strings.ToLower(globalConfiguration.LogLevel) | ||||
| 	if levelStr == "" { | ||||
| 		levelStr = "error" | ||||
| 		if globalConfiguration.Debug { | ||||
| 			levelStr = "debug" | ||||
| 		} | ||||
| 	} | ||||
| 	level, err := logrus.ParseLevel(levelStr) | ||||
| 	ctx := context.Background() | ||||
| 	routinesPool := safe.NewPool(ctx) | ||||
|  | ||||
| 	// adds internal provider | ||||
| 	err := providerAggregator.AddProvider(traefik.New(*staticConfiguration)) | ||||
| 	if err != nil { | ||||
| 		log.Error("Error getting level", err) | ||||
| 	} | ||||
| 	log.SetLevel(level) | ||||
|  | ||||
| 	// configure log output file | ||||
| 	logFile := globalConfiguration.TraefikLogsFile | ||||
| 	if len(logFile) > 0 { | ||||
| 		log.Warn("top-level traefikLogsFile has been deprecated -- please use traefiklog.filepath") | ||||
| 	} | ||||
| 	if globalConfiguration.TraefikLog != nil && len(globalConfiguration.TraefikLog.FilePath) > 0 { | ||||
| 		logFile = globalConfiguration.TraefikLog.FilePath | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	// configure log format | ||||
| 	var formatter logrus.Formatter | ||||
| 	if globalConfiguration.TraefikLog != nil && globalConfiguration.TraefikLog.Format == "json" { | ||||
| 		formatter = &logrus.JSONFormatter{} | ||||
| 	} else { | ||||
| 		disableColors := len(logFile) > 0 | ||||
| 		formatter = &logrus.TextFormatter{DisableColors: disableColors, FullTimestamp: true, DisableSorting: true} | ||||
| 	// ACME | ||||
|  | ||||
| 	tlsManager := traefiktls.NewManager() | ||||
| 	httpChallengeProvider := acme.NewChallengeHTTP() | ||||
|  | ||||
| 	tlsChallengeProvider := acme.NewChallengeTLSALPN() | ||||
| 	err = providerAggregator.AddProvider(tlsChallengeProvider) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
| 	log.SetFormatter(formatter) | ||||
|  | ||||
| 	if len(logFile) > 0 { | ||||
| 		dir := filepath.Dir(logFile) | ||||
| 	acmeProviders := initACMEProvider(staticConfiguration, &providerAggregator, tlsManager, httpChallengeProvider, tlsChallengeProvider) | ||||
|  | ||||
| 		if err := os.MkdirAll(dir, 0755); err != nil { | ||||
| 			log.Errorf("Failed to create log path %s: %s", dir, err) | ||||
| 		} | ||||
| 	// Tailscale | ||||
|  | ||||
| 		err = log.OpenFile(logFile) | ||||
| 		logrus.RegisterExitHandler(func() { | ||||
| 			if err := log.CloseFile(); err != nil { | ||||
| 				log.Error("Error closing log", err) | ||||
| 			} | ||||
| 		}) | ||||
| 	tsProviders := initTailscaleProviders(staticConfiguration, &providerAggregator) | ||||
|  | ||||
| 	// Observability | ||||
|  | ||||
| 	metricRegistries := registerMetricClients(staticConfiguration.Metrics) | ||||
| 	var semConvMetricRegistry *metrics.SemConvMetricsRegistry | ||||
| 	if staticConfiguration.Metrics != nil && staticConfiguration.Metrics.OTLP != nil { | ||||
| 		semConvMetricRegistry, err = metrics.NewSemConvMetricRegistry(ctx, staticConfiguration.Metrics.OTLP) | ||||
| 		if err != nil { | ||||
| 			log.Error("Error opening file", err) | ||||
| 			return nil, fmt.Errorf("unable to create SemConv metric registry: %w", err) | ||||
| 		} | ||||
| 	} | ||||
| 	metricsRegistry := metrics.NewMultiRegistry(metricRegistries) | ||||
| 	accessLog := setupAccessLog(staticConfiguration.AccessLog) | ||||
| 	tracer, tracerCloser := setupTracing(staticConfiguration.Tracing) | ||||
| 	observabilityMgr := middleware.NewObservabilityMgr(*staticConfiguration, metricsRegistry, semConvMetricRegistry, accessLog, tracer, tracerCloser) | ||||
|  | ||||
| 	// Entrypoints | ||||
|  | ||||
| 	serverEntryPointsTCP, err := server.NewTCPEntryPoints(staticConfiguration.EntryPoints, staticConfiguration.HostResolver, metricsRegistry) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	serverEntryPointsUDP, err := server.NewUDPEntryPoints(staticConfiguration.EntryPoints) | ||||
| 	if err != nil { | ||||
| 		return nil, err | ||||
| 	} | ||||
|  | ||||
| 	if staticConfiguration.API != nil { | ||||
| 		version.DisableDashboardAd = staticConfiguration.API.DisableDashboardAd | ||||
| 	} | ||||
|  | ||||
| 	// Plugins | ||||
| 	pluginLogger := log.Ctx(ctx).With().Logger() | ||||
| 	hasPlugins := staticConfiguration.Experimental != nil && (staticConfiguration.Experimental.Plugins != nil || staticConfiguration.Experimental.LocalPlugins != nil) | ||||
| 	if hasPlugins { | ||||
| 		pluginsList := maps.Keys(staticConfiguration.Experimental.Plugins) | ||||
| 		pluginsList = append(pluginsList, maps.Keys(staticConfiguration.Experimental.LocalPlugins)...) | ||||
|  | ||||
| 		pluginLogger = pluginLogger.With().Strs("plugins", pluginsList).Logger() | ||||
| 		pluginLogger.Info().Msg("Loading plugins...") | ||||
| 	} | ||||
|  | ||||
| 	pluginBuilder, err := createPluginBuilder(staticConfiguration) | ||||
| 	if err != nil { | ||||
| 		pluginLogger.Err(err).Msg("Plugins are disabled because an error has occurred.") | ||||
| 	} else if hasPlugins { | ||||
| 		pluginLogger.Info().Msg("Plugins loaded.") | ||||
| 	} | ||||
|  | ||||
| 	// Providers plugins | ||||
|  | ||||
| 	for name, conf := range staticConfiguration.Providers.Plugin { | ||||
| 		if pluginBuilder == nil { | ||||
| 			break | ||||
| 		} | ||||
|  | ||||
| 		p, err := pluginBuilder.BuildProvider(name, conf) | ||||
| 		if err != nil { | ||||
| 			return nil, fmt.Errorf("plugin: failed to build provider: %w", err) | ||||
| 		} | ||||
|  | ||||
| 		err = providerAggregator.AddProvider(p) | ||||
| 		if err != nil { | ||||
| 			return nil, fmt.Errorf("plugin: failed to add provider: %w", err) | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	// Service manager factory | ||||
|  | ||||
| 	var spiffeX509Source *workloadapi.X509Source | ||||
| 	if staticConfiguration.Spiffe != nil && staticConfiguration.Spiffe.WorkloadAPIAddr != "" { | ||||
| 		log.Info().Str("workloadAPIAddr", staticConfiguration.Spiffe.WorkloadAPIAddr). | ||||
| 			Msg("Waiting on SPIFFE SVID delivery") | ||||
|  | ||||
| 		spiffeX509Source, err = workloadapi.NewX509Source( | ||||
| 			ctx, | ||||
| 			workloadapi.WithClientOptions( | ||||
| 				workloadapi.WithAddr( | ||||
| 					staticConfiguration.Spiffe.WorkloadAPIAddr, | ||||
| 				), | ||||
| 			), | ||||
| 		) | ||||
| 		if err != nil { | ||||
| 			return nil, fmt.Errorf("unable to create SPIFFE x509 source: %w", err) | ||||
| 		} | ||||
| 		log.Info().Msg("Successfully obtained SPIFFE SVID.") | ||||
| 	} | ||||
|  | ||||
| 	roundTripperManager := service.NewRoundTripperManager(spiffeX509Source) | ||||
| 	dialerManager := tcp.NewDialerManager(spiffeX509Source) | ||||
| 	acmeHTTPHandler := getHTTPChallengeHandler(acmeProviders, httpChallengeProvider) | ||||
| 	managerFactory := service.NewManagerFactory(*staticConfiguration, routinesPool, observabilityMgr, roundTripperManager, acmeHTTPHandler) | ||||
|  | ||||
| 	// Router factory | ||||
|  | ||||
| 	routerFactory := server.NewRouterFactory(*staticConfiguration, managerFactory, tlsManager, observabilityMgr, pluginBuilder, dialerManager) | ||||
|  | ||||
| 	// Watcher | ||||
|  | ||||
| 	watcher := server.NewConfigurationWatcher( | ||||
| 		routinesPool, | ||||
| 		providerAggregator, | ||||
| 		getDefaultsEntrypoints(staticConfiguration), | ||||
| 		"internal", | ||||
| 	) | ||||
|  | ||||
| 	// TLS | ||||
| 	watcher.AddListener(func(conf dynamic.Configuration) { | ||||
| 		ctx := context.Background() | ||||
| 		tlsManager.UpdateConfigs(ctx, conf.TLS.Stores, conf.TLS.Options, conf.TLS.Certificates) | ||||
|  | ||||
| 		gauge := metricsRegistry.TLSCertsNotAfterTimestampGauge() | ||||
| 		for _, certificate := range tlsManager.GetServerCertificates() { | ||||
| 			appendCertMetric(gauge, certificate) | ||||
| 		} | ||||
| 	}) | ||||
|  | ||||
| 	// Metrics | ||||
| 	watcher.AddListener(func(_ dynamic.Configuration) { | ||||
| 		metricsRegistry.ConfigReloadsCounter().Add(1) | ||||
| 		metricsRegistry.LastConfigReloadSuccessGauge().Set(float64(time.Now().Unix())) | ||||
| 	}) | ||||
|  | ||||
| 	// Server Transports | ||||
| 	watcher.AddListener(func(conf dynamic.Configuration) { | ||||
| 		roundTripperManager.Update(conf.HTTP.ServersTransports) | ||||
| 		dialerManager.Update(conf.TCP.ServersTransports) | ||||
| 	}) | ||||
|  | ||||
| 	// Switch router | ||||
| 	watcher.AddListener(switchRouter(routerFactory, serverEntryPointsTCP, serverEntryPointsUDP)) | ||||
|  | ||||
| 	// Metrics | ||||
| 	if metricsRegistry.IsEpEnabled() || metricsRegistry.IsRouterEnabled() || metricsRegistry.IsSvcEnabled() { | ||||
| 		var eps []string | ||||
| 		for key := range serverEntryPointsTCP { | ||||
| 			eps = append(eps, key) | ||||
| 		} | ||||
| 		watcher.AddListener(func(conf dynamic.Configuration) { | ||||
| 			metrics.OnConfigurationUpdate(conf, eps) | ||||
| 		}) | ||||
| 	} | ||||
|  | ||||
| 	// TLS challenge | ||||
| 	watcher.AddListener(tlsChallengeProvider.ListenConfiguration) | ||||
|  | ||||
| 	// Certificate Resolvers | ||||
|  | ||||
| 	resolverNames := map[string]struct{}{} | ||||
|  | ||||
| 	// ACME | ||||
| 	for _, p := range acmeProviders { | ||||
| 		resolverNames[p.ResolverName] = struct{}{} | ||||
| 		watcher.AddListener(p.ListenConfiguration) | ||||
| 	} | ||||
|  | ||||
| 	// Tailscale | ||||
| 	for _, p := range tsProviders { | ||||
| 		resolverNames[p.ResolverName] = struct{}{} | ||||
| 		watcher.AddListener(p.HandleConfigUpdate) | ||||
| 	} | ||||
|  | ||||
| 	// Certificate resolver logs | ||||
| 	watcher.AddListener(func(config dynamic.Configuration) { | ||||
| 		for rtName, rt := range config.HTTP.Routers { | ||||
| 			if rt.TLS == nil || rt.TLS.CertResolver == "" { | ||||
| 				continue | ||||
| 			} | ||||
|  | ||||
| 			if _, ok := resolverNames[rt.TLS.CertResolver]; !ok { | ||||
| 				log.Error().Err(err).Str(logs.RouterName, rtName).Str("certificateResolver", rt.TLS.CertResolver). | ||||
| 					Msg("Router uses a non-existent certificate resolver") | ||||
| 			} | ||||
| 		} | ||||
| 	}) | ||||
|  | ||||
| 	return server.NewServer(routinesPool, serverEntryPointsTCP, serverEntryPointsUDP, watcher, observabilityMgr), nil | ||||
| } | ||||
|  | ||||
| func getHTTPChallengeHandler(acmeProviders []*acme.Provider, httpChallengeProvider http.Handler) http.Handler { | ||||
| 	var acmeHTTPHandler http.Handler | ||||
| 	for _, p := range acmeProviders { | ||||
| 		if p != nil && p.HTTPChallenge != nil { | ||||
| 			acmeHTTPHandler = httpChallengeProvider | ||||
| 			break | ||||
| 		} | ||||
| 	} | ||||
| 	return acmeHTTPHandler | ||||
| } | ||||
|  | ||||
| func getDefaultsEntrypoints(staticConfiguration *static.Configuration) []string { | ||||
| 	var defaultEntryPoints []string | ||||
|  | ||||
| 	// Determines if at least one EntryPoint is configured to be used by default. | ||||
| 	var hasDefinedDefaults bool | ||||
| 	for _, ep := range staticConfiguration.EntryPoints { | ||||
| 		if ep.AsDefault { | ||||
| 			hasDefinedDefaults = true | ||||
| 			break | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	for name, cfg := range staticConfiguration.EntryPoints { | ||||
| 		// By default all entrypoints are considered. | ||||
| 		// If at least one is flagged, then only flagged entrypoints are included. | ||||
| 		if hasDefinedDefaults && !cfg.AsDefault { | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		protocol, err := cfg.GetProtocol() | ||||
| 		if err != nil { | ||||
| 			// Should never happen because Traefik should not start if protocol is invalid. | ||||
| 			log.Error().Err(err).Msg("Invalid protocol") | ||||
| 		} | ||||
|  | ||||
| 		if protocol != "udp" && name != static.DefaultInternalEntryPointName { | ||||
| 			defaultEntryPoints = append(defaultEntryPoints, name) | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	sort.Strings(defaultEntryPoints) | ||||
| 	return defaultEntryPoints | ||||
| } | ||||
|  | ||||
| func switchRouter(routerFactory *server.RouterFactory, serverEntryPointsTCP server.TCPEntryPoints, serverEntryPointsUDP server.UDPEntryPoints) func(conf dynamic.Configuration) { | ||||
| 	return func(conf dynamic.Configuration) { | ||||
| 		rtConf := runtime.NewConfig(conf) | ||||
|  | ||||
| 		routers, udpRouters := routerFactory.CreateRouters(rtConf) | ||||
|  | ||||
| 		serverEntryPointsTCP.Switch(routers) | ||||
| 		serverEntryPointsUDP.Switch(udpRouters) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // initACMEProvider creates and registers acme.Provider instances corresponding to the configured ACME certificate resolvers. | ||||
| func initACMEProvider(c *static.Configuration, providerAggregator *aggregator.ProviderAggregator, tlsManager *traefiktls.Manager, httpChallengeProvider, tlsChallengeProvider challenge.Provider) []*acme.Provider { | ||||
| 	localStores := map[string]*acme.LocalStore{} | ||||
|  | ||||
| 	var resolvers []*acme.Provider | ||||
| 	for name, resolver := range c.CertificatesResolvers { | ||||
| 		if resolver.ACME == nil { | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		if localStores[resolver.ACME.Storage] == nil { | ||||
| 			localStores[resolver.ACME.Storage] = acme.NewLocalStore(resolver.ACME.Storage) | ||||
| 		} | ||||
|  | ||||
| 		p := &acme.Provider{ | ||||
| 			Configuration:         resolver.ACME, | ||||
| 			Store:                 localStores[resolver.ACME.Storage], | ||||
| 			ResolverName:          name, | ||||
| 			HTTPChallengeProvider: httpChallengeProvider, | ||||
| 			TLSChallengeProvider:  tlsChallengeProvider, | ||||
| 		} | ||||
|  | ||||
| 		if err := providerAggregator.AddProvider(p); err != nil { | ||||
| 			log.Error().Err(err).Str("resolver", name).Msg("The ACME resolve is skipped from the resolvers list") | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		p.SetTLSManager(tlsManager) | ||||
|  | ||||
| 		p.SetConfigListenerChan(make(chan dynamic.Configuration)) | ||||
|  | ||||
| 		resolvers = append(resolvers, p) | ||||
| 	} | ||||
|  | ||||
| 	return resolvers | ||||
| } | ||||
|  | ||||
| // initTailscaleProviders creates and registers tailscale.Provider instances corresponding to the configured Tailscale certificate resolvers. | ||||
| func initTailscaleProviders(cfg *static.Configuration, providerAggregator *aggregator.ProviderAggregator) []*tailscale.Provider { | ||||
| 	var providers []*tailscale.Provider | ||||
| 	for name, resolver := range cfg.CertificatesResolvers { | ||||
| 		if resolver.Tailscale == nil { | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		tsProvider := &tailscale.Provider{ResolverName: name} | ||||
|  | ||||
| 		if err := providerAggregator.AddProvider(tsProvider); err != nil { | ||||
| 			log.Error().Err(err).Str(logs.ProviderName, name).Msg("Unable to create Tailscale provider") | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		providers = append(providers, tsProvider) | ||||
| 	} | ||||
|  | ||||
| 	return providers | ||||
| } | ||||
|  | ||||
| func registerMetricClients(metricsConfig *types.Metrics) []metrics.Registry { | ||||
| 	if metricsConfig == nil { | ||||
| 		return nil | ||||
| 	} | ||||
|  | ||||
| 	var registries []metrics.Registry | ||||
|  | ||||
| 	if metricsConfig.Prometheus != nil { | ||||
| 		logger := log.With().Str(logs.MetricsProviderName, "prometheus").Logger() | ||||
|  | ||||
| 		prometheusRegister := metrics.RegisterPrometheus(logger.WithContext(context.Background()), metricsConfig.Prometheus) | ||||
| 		if prometheusRegister != nil { | ||||
| 			registries = append(registries, prometheusRegister) | ||||
| 			logger.Debug().Msg("Configured Prometheus metrics") | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if metricsConfig.Datadog != nil { | ||||
| 		logger := log.With().Str(logs.MetricsProviderName, "datadog").Logger() | ||||
|  | ||||
| 		registries = append(registries, metrics.RegisterDatadog(logger.WithContext(context.Background()), metricsConfig.Datadog)) | ||||
| 		logger.Debug(). | ||||
| 			Str("address", metricsConfig.Datadog.Address). | ||||
| 			Str("pushInterval", metricsConfig.Datadog.PushInterval.String()). | ||||
| 			Msgf("Configured Datadog metrics") | ||||
| 	} | ||||
|  | ||||
| 	if metricsConfig.StatsD != nil { | ||||
| 		logger := log.With().Str(logs.MetricsProviderName, "statsd").Logger() | ||||
|  | ||||
| 		registries = append(registries, metrics.RegisterStatsd(logger.WithContext(context.Background()), metricsConfig.StatsD)) | ||||
| 		logger.Debug(). | ||||
| 			Str("address", metricsConfig.StatsD.Address). | ||||
| 			Str("pushInterval", metricsConfig.StatsD.PushInterval.String()). | ||||
| 			Msg("Configured StatsD metrics") | ||||
| 	} | ||||
|  | ||||
| 	if metricsConfig.InfluxDB2 != nil { | ||||
| 		logger := log.With().Str(logs.MetricsProviderName, "influxdb2").Logger() | ||||
|  | ||||
| 		influxDB2Register := metrics.RegisterInfluxDB2(logger.WithContext(context.Background()), metricsConfig.InfluxDB2) | ||||
| 		if influxDB2Register != nil { | ||||
| 			registries = append(registries, influxDB2Register) | ||||
| 			logger.Debug(). | ||||
| 				Str("address", metricsConfig.InfluxDB2.Address). | ||||
| 				Str("bucket", metricsConfig.InfluxDB2.Bucket). | ||||
| 				Str("organization", metricsConfig.InfluxDB2.Org). | ||||
| 				Str("pushInterval", metricsConfig.InfluxDB2.PushInterval.String()). | ||||
| 				Msg("Configured InfluxDB v2 metrics") | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if metricsConfig.OTLP != nil { | ||||
| 		logger := log.With().Str(logs.MetricsProviderName, "openTelemetry").Logger() | ||||
|  | ||||
| 		openTelemetryRegistry := metrics.RegisterOpenTelemetry(logger.WithContext(context.Background()), metricsConfig.OTLP) | ||||
| 		if openTelemetryRegistry != nil { | ||||
| 			registries = append(registries, openTelemetryRegistry) | ||||
| 			logger.Debug(). | ||||
| 				Str("pushInterval", metricsConfig.OTLP.PushInterval.String()). | ||||
| 				Msg("Configured OpenTelemetry metrics") | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return registries | ||||
| } | ||||
|  | ||||
| func appendCertMetric(gauge gokitmetrics.Gauge, certificate *x509.Certificate) { | ||||
| 	sort.Strings(certificate.DNSNames) | ||||
|  | ||||
| 	labels := []string{ | ||||
| 		"cn", certificate.Subject.CommonName, | ||||
| 		"serial", certificate.SerialNumber.String(), | ||||
| 		"sans", strings.Join(certificate.DNSNames, ","), | ||||
| 	} | ||||
|  | ||||
| 	notAfter := float64(certificate.NotAfter.Unix()) | ||||
|  | ||||
| 	gauge.With(labels...).Set(notAfter) | ||||
| } | ||||
|  | ||||
| func setupAccessLog(conf *types.AccessLog) *accesslog.Handler { | ||||
| 	if conf == nil { | ||||
| 		return nil | ||||
| 	} | ||||
|  | ||||
| 	accessLoggerMiddleware, err := accesslog.NewHandler(conf) | ||||
| 	if err != nil { | ||||
| 		log.Warn().Err(err).Msg("Unable to create access logger") | ||||
| 		return nil | ||||
| 	} | ||||
|  | ||||
| 	return accessLoggerMiddleware | ||||
| } | ||||
|  | ||||
| func setupTracing(conf *static.Tracing) (*tracing.Tracer, io.Closer) { | ||||
| 	if conf == nil { | ||||
| 		return nil, nil | ||||
| 	} | ||||
|  | ||||
| 	tracer, closer, err := tracing.NewTracing(conf) | ||||
| 	if err != nil { | ||||
| 		log.Warn().Err(err).Msg("Unable to create tracer") | ||||
| 		return nil, nil | ||||
| 	} | ||||
|  | ||||
| 	return tracer, closer | ||||
| } | ||||
|  | ||||
| func checkNewVersion() { | ||||
| @@ -281,30 +604,30 @@ func checkNewVersion() { | ||||
| 	}) | ||||
| } | ||||
|  | ||||
| func stats(globalConfiguration *configuration.GlobalConfiguration) { | ||||
| 	if globalConfiguration.SendAnonymousUsage { | ||||
| 		log.Info(` | ||||
| Stats collection is enabled. | ||||
| Many thanks for contributing to Traefik's improvement by allowing us to receive anonymous information from your configuration. | ||||
| Help us improve Traefik by leaving this feature on :) | ||||
| More details on: https://docs.traefik.io/basics/#collected-data | ||||
| `) | ||||
| 		collect(globalConfiguration) | ||||
| func stats(staticConfiguration *static.Configuration) { | ||||
| 	logger := log.With().Logger() | ||||
|  | ||||
| 	if staticConfiguration.Global.SendAnonymousUsage { | ||||
| 		logger.Info().Msg(`Stats collection is enabled.`) | ||||
| 		logger.Info().Msg(`Many thanks for contributing to Traefik's improvement by allowing us to receive anonymous information from your configuration.`) | ||||
| 		logger.Info().Msg(`Help us improve Traefik by leaving this feature on :)`) | ||||
| 		logger.Info().Msg(`More details on: https://doc.traefik.io/traefik/contributing/data-collection/`) | ||||
| 		collect(staticConfiguration) | ||||
| 	} else { | ||||
| 		log.Info(` | ||||
| 		logger.Info().Msg(` | ||||
| Stats collection is disabled. | ||||
| Help us improve Traefik by turning this feature on :) | ||||
| More details on: https://docs.traefik.io/basics/#collected-data | ||||
| More details on: https://doc.traefik.io/traefik/contributing/data-collection/ | ||||
| `) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func collect(globalConfiguration *configuration.GlobalConfiguration) { | ||||
| func collect(staticConfiguration *static.Configuration) { | ||||
| 	ticker := time.Tick(24 * time.Hour) | ||||
| 	safe.Go(func() { | ||||
| 		for time.Sleep(10 * time.Minute); ; <-ticker { | ||||
| 			if err := collector.Collect(globalConfiguration); err != nil { | ||||
| 				log.Debug(err) | ||||
| 			if err := collector.Collect(staticConfiguration); err != nil { | ||||
| 				log.Debug().Err(err).Send() | ||||
| 			} | ||||
| 		} | ||||
| 	}) | ||||
|   | ||||
							
								
								
									
										186
									
								
								cmd/traefik/traefik_test.go
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										186
									
								
								cmd/traefik/traefik_test.go
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,186 @@ | ||||
| package main | ||||
|  | ||||
| import ( | ||||
| 	"crypto/x509" | ||||
| 	"encoding/pem" | ||||
| 	"strings" | ||||
| 	"testing" | ||||
|  | ||||
| 	"github.com/go-kit/kit/metrics" | ||||
| 	"github.com/stretchr/testify/assert" | ||||
| 	"github.com/stretchr/testify/require" | ||||
| 	"github.com/traefik/traefik/v3/pkg/config/static" | ||||
| ) | ||||
|  | ||||
| // FooCert is a PEM-encoded TLS cert. | ||||
| // generated from src/crypto/tls: | ||||
| // go run generate_cert.go  --rsa-bits 1024 --host foo.org,foo.com  --ca --start-date "Jan 1 00:00:00 1970" --duration=1000000h | ||||
| const fooCert = `-----BEGIN CERTIFICATE----- | ||||
| MIICHzCCAYigAwIBAgIQXQFLeYRwc5X21t457t2xADANBgkqhkiG9w0BAQsFADAS | ||||
| MRAwDgYDVQQKEwdBY21lIENvMCAXDTcwMDEwMTAwMDAwMFoYDzIwODQwMTI5MTYw | ||||
| MDAwWjASMRAwDgYDVQQKEwdBY21lIENvMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCB | ||||
| iQKBgQDCjn67GSs/khuGC4GNN+tVo1S+/eSHwr/hWzhfMqO7nYiXkFzmxi+u14CU | ||||
| Pda6WOeps7T2/oQEFMxKKg7zYOqkLSbjbE0ZfosopaTvEsZm/AZHAAvoOrAsIJOn | ||||
| SEiwy8h0tLA4z1SNR6rmIVQWyqBZEPAhBTQM1z7tFp48FakCFwIDAQABo3QwcjAO | ||||
| BgNVHQ8BAf8EBAMCAqQwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDwYDVR0TAQH/BAUw | ||||
| AwEB/zAdBgNVHQ4EFgQUDHG3ASzeUezElup9zbPpBn/vjogwGwYDVR0RBBQwEoIH | ||||
| Zm9vLm9yZ4IHZm9vLmNvbTANBgkqhkiG9w0BAQsFAAOBgQBT+VLMbB9u27tBX8Aw | ||||
| ZrGY3rbNdBGhXVTksrjiF+6ZtDpD3iI56GH9zLxnqvXkgn3u0+Ard5TqF/xmdwVw | ||||
| NY0V/aWYfcL2G2auBCQrPvM03ozRnVUwVfP23eUzX2ORNHCYhd2ObQx4krrhs7cJ | ||||
| SWxtKwFlstoXY3K2g9oRD9UxdQ== | ||||
| -----END CERTIFICATE-----` | ||||
|  | ||||
| // BarCert is a PEM-encoded TLS cert. | ||||
| // generated from src/crypto/tls: | ||||
| // go run generate_cert.go  --rsa-bits 1024 --host bar.org,bar.com  --ca --start-date "Jan 1 00:00:00 1970" --duration=10000h | ||||
| const barCert = `-----BEGIN CERTIFICATE----- | ||||
| MIICHTCCAYagAwIBAgIQcuIcNEXzBHPoxna5S6wG4jANBgkqhkiG9w0BAQsFADAS | ||||
| MRAwDgYDVQQKEwdBY21lIENvMB4XDTcwMDEwMTAwMDAwMFoXDTcxMDIyMTE2MDAw | ||||
| MFowEjEQMA4GA1UEChMHQWNtZSBDbzCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkC | ||||
| gYEAqtcrP+KA7D6NjyztGNIPMup9KiBMJ8QL+preog/YHR7SQLO3kGFhpS3WKMab | ||||
| SzMypC3ZX1PZjBP5ZzwaV3PFbuwlCkPlyxR2lOWmullgI7mjY0TBeYLDIclIzGRp | ||||
| mpSDDSpkW1ay2iJDSpXjlhmwZr84hrCU7BRTQJo91fdsRTsCAwEAAaN0MHIwDgYD | ||||
| VR0PAQH/BAQDAgKkMBMGA1UdJQQMMAoGCCsGAQUFBwMBMA8GA1UdEwEB/wQFMAMB | ||||
| Af8wHQYDVR0OBBYEFK8jnzFQvBAgWtfzOyXY4VSkwrTXMBsGA1UdEQQUMBKCB2Jh | ||||
| ci5vcmeCB2Jhci5jb20wDQYJKoZIhvcNAQELBQADgYEAJz0ifAExisC/ZSRhWuHz | ||||
| 7qs1i6Nd4+YgEVR8dR71MChP+AMxucY1/ajVjb9xlLys3GPE90TWSdVppabEVjZY | ||||
| Oq11nPKc50ItTt8dMku6t0JHBmzoGdkN0V4zJCBqdQJxhop8JpYJ0S9CW0eT93h3 | ||||
| ipYQSsmIINGtMXJ8VkP/MlM= | ||||
| -----END CERTIFICATE-----` | ||||
|  | ||||
| type gaugeMock struct { | ||||
| 	metrics map[string]float64 | ||||
| 	labels  string | ||||
| } | ||||
|  | ||||
| func (g gaugeMock) With(labelValues ...string) metrics.Gauge { | ||||
| 	g.labels = strings.Join(labelValues, ",") | ||||
| 	return g | ||||
| } | ||||
|  | ||||
| func (g gaugeMock) Set(value float64) { | ||||
| 	g.metrics[g.labels] = value | ||||
| } | ||||
|  | ||||
| func (g gaugeMock) Add(delta float64) { | ||||
| 	panic("implement me") | ||||
| } | ||||
|  | ||||
| func TestAppendCertMetric(t *testing.T) { | ||||
| 	testCases := []struct { | ||||
| 		desc     string | ||||
| 		certs    []string | ||||
| 		expected map[string]float64 | ||||
| 	}{ | ||||
| 		{ | ||||
| 			desc:     "No certs", | ||||
| 			certs:    []string{}, | ||||
| 			expected: map[string]float64{}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:  "One cert", | ||||
| 			certs: []string{fooCert}, | ||||
| 			expected: map[string]float64{ | ||||
| 				"cn,,serial,123624926713171615935660664614975025408,sans,foo.com,foo.org": 3.6e+09, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:  "Two certs", | ||||
| 			certs: []string{fooCert, barCert}, | ||||
| 			expected: map[string]float64{ | ||||
| 				"cn,,serial,123624926713171615935660664614975025408,sans,foo.com,foo.org": 3.6e+09, | ||||
| 				"cn,,serial,152706022658490889223053211416725817058,sans,bar.com,bar.org": 3.6e+07, | ||||
| 			}, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range testCases { | ||||
| 		t.Run(test.desc, func(t *testing.T) { | ||||
| 			t.Parallel() | ||||
|  | ||||
| 			gauge := &gaugeMock{ | ||||
| 				metrics: map[string]float64{}, | ||||
| 			} | ||||
|  | ||||
| 			for _, cert := range test.certs { | ||||
| 				block, _ := pem.Decode([]byte(cert)) | ||||
| 				parsedCert, err := x509.ParseCertificate(block.Bytes) | ||||
| 				require.NoError(t, err) | ||||
|  | ||||
| 				appendCertMetric(gauge, parsedCert) | ||||
| 			} | ||||
|  | ||||
| 			assert.Equal(t, test.expected, gauge.metrics) | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestGetDefaultsEntrypoints(t *testing.T) { | ||||
| 	testCases := []struct { | ||||
| 		desc        string | ||||
| 		entrypoints static.EntryPoints | ||||
| 		expected    []string | ||||
| 	}{ | ||||
| 		{ | ||||
| 			desc: "Skips special names", | ||||
| 			entrypoints: map[string]*static.EntryPoint{ | ||||
| 				"web": { | ||||
| 					Address: ":80", | ||||
| 				}, | ||||
| 				"traefik": { | ||||
| 					Address: ":8080", | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: []string{"web"}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc: "Two EntryPoints not attachable", | ||||
| 			entrypoints: map[string]*static.EntryPoint{ | ||||
| 				"web": { | ||||
| 					Address: ":80", | ||||
| 				}, | ||||
| 				"websecure": { | ||||
| 					Address: ":443", | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: []string{"web", "websecure"}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc: "Two EntryPoints only one attachable", | ||||
| 			entrypoints: map[string]*static.EntryPoint{ | ||||
| 				"web": { | ||||
| 					Address: ":80", | ||||
| 				}, | ||||
| 				"websecure": { | ||||
| 					Address:   ":443", | ||||
| 					AsDefault: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: []string{"websecure"}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc: "Two attachable EntryPoints", | ||||
| 			entrypoints: map[string]*static.EntryPoint{ | ||||
| 				"web": { | ||||
| 					Address:   ":80", | ||||
| 					AsDefault: true, | ||||
| 				}, | ||||
| 				"websecure": { | ||||
| 					Address:   ":443", | ||||
| 					AsDefault: true, | ||||
| 				}, | ||||
| 			}, | ||||
| 			expected: []string{"web", "websecure"}, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range testCases { | ||||
| 		t.Run(test.desc, func(t *testing.T) { | ||||
| 			actual := getDefaultsEntrypoints(&static.Configuration{ | ||||
| 				EntryPoints: test.entrypoints, | ||||
| 			}) | ||||
|  | ||||
| 			assert.ElementsMatch(t, test.expected, actual) | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
| @@ -7,8 +7,8 @@ import ( | ||||
| 	"runtime" | ||||
| 	"text/template" | ||||
|  | ||||
| 	"github.com/containous/flaeg" | ||||
| 	"github.com/containous/traefik/version" | ||||
| 	"github.com/traefik/paerser/cli" | ||||
| 	"github.com/traefik/traefik/v3/pkg/version" | ||||
| ) | ||||
|  | ||||
| var versionTemplate = `Version:      {{.Version}} | ||||
| @@ -17,25 +17,23 @@ Go version:   {{.GoVersion}} | ||||
| Built:        {{.BuildTime}} | ||||
| OS/Arch:      {{.Os}}/{{.Arch}}` | ||||
|  | ||||
| // NewCmd builds a new Version command | ||||
| func NewCmd() *flaeg.Command { | ||||
| 	return &flaeg.Command{ | ||||
| 		Name:                  "version", | ||||
| 		Description:           `Print version`, | ||||
| 		Config:                struct{}{}, | ||||
| 		DefaultPointersConfig: struct{}{}, | ||||
| 		Run: func() error { | ||||
| // NewCmd builds a new Version command. | ||||
| func NewCmd() *cli.Command { | ||||
| 	return &cli.Command{ | ||||
| 		Name:          "version", | ||||
| 		Description:   `Shows the current Traefik version.`, | ||||
| 		Configuration: nil, | ||||
| 		Run: func(_ []string) error { | ||||
| 			if err := GetPrint(os.Stdout); err != nil { | ||||
| 				return err | ||||
| 			} | ||||
| 			fmt.Print("\n") | ||||
| 			return nil | ||||
|  | ||||
| 		}, | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // GetPrint write Printable version | ||||
| // GetPrint write Printable version. | ||||
| func GetPrint(wr io.Writer) error { | ||||
| 	tmpl, err := template.New("").Parse(versionTemplate) | ||||
| 	if err != nil { | ||||
|   | ||||
| @@ -1,79 +0,0 @@ | ||||
| package collector | ||||
|  | ||||
| import ( | ||||
| 	"bytes" | ||||
| 	"encoding/base64" | ||||
| 	"encoding/json" | ||||
| 	"net" | ||||
| 	"net/http" | ||||
| 	"strconv" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/containous/traefik/anonymize" | ||||
| 	"github.com/containous/traefik/configuration" | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/version" | ||||
| 	"github.com/mitchellh/hashstructure" | ||||
| ) | ||||
|  | ||||
| // collectorURL URL where the stats are send | ||||
| const collectorURL = "https://collect.traefik.io/619df80498b60f985d766ce62f912b7c" | ||||
|  | ||||
| // Collected data | ||||
| type data struct { | ||||
| 	Version       string | ||||
| 	Codename      string | ||||
| 	BuildDate     string | ||||
| 	Configuration string | ||||
| 	Hash          string | ||||
| } | ||||
|  | ||||
| // Collect anonymous data. | ||||
| func Collect(globalConfiguration *configuration.GlobalConfiguration) error { | ||||
| 	anonConfig, err := anonymize.Do(globalConfiguration, false) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	log.Infof("Anonymous stats sent to %s: %s", collectorURL, anonConfig) | ||||
|  | ||||
| 	hashConf, err := hashstructure.Hash(globalConfiguration, nil) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	data := &data{ | ||||
| 		Version:       version.Version, | ||||
| 		Codename:      version.Codename, | ||||
| 		BuildDate:     version.BuildDate, | ||||
| 		Hash:          strconv.FormatUint(hashConf, 10), | ||||
| 		Configuration: base64.StdEncoding.EncodeToString([]byte(anonConfig)), | ||||
| 	} | ||||
|  | ||||
| 	buf := new(bytes.Buffer) | ||||
| 	err = json.NewEncoder(buf).Encode(data) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	_, err = makeHTTPClient().Post(collectorURL, "application/json; charset=utf-8", buf) | ||||
| 	return err | ||||
| } | ||||
|  | ||||
| func makeHTTPClient() *http.Client { | ||||
| 	dialer := &net.Dialer{ | ||||
| 		Timeout:   configuration.DefaultDialTimeout, | ||||
| 		KeepAlive: 30 * time.Second, | ||||
| 		DualStack: true, | ||||
| 	} | ||||
|  | ||||
| 	transport := &http.Transport{ | ||||
| 		Proxy:                 http.ProxyFromEnvironment, | ||||
| 		DialContext:           dialer.DialContext, | ||||
| 		IdleConnTimeout:       90 * time.Second, | ||||
| 		TLSHandshakeTimeout:   10 * time.Second, | ||||
| 		ExpectContinueTimeout: 1 * time.Second, | ||||
| 	} | ||||
|  | ||||
| 	return &http.Client{Transport: transport} | ||||
| } | ||||
| @@ -1,414 +0,0 @@ | ||||
| package configuration | ||||
|  | ||||
| import ( | ||||
| 	"fmt" | ||||
| 	"strings" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/containous/flaeg" | ||||
| 	"github.com/containous/traefik-extra-service-fabric" | ||||
| 	"github.com/containous/traefik/acme" | ||||
| 	"github.com/containous/traefik/api" | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/middlewares/tracing" | ||||
| 	"github.com/containous/traefik/ping" | ||||
| 	acmeprovider "github.com/containous/traefik/provider/acme" | ||||
| 	"github.com/containous/traefik/provider/boltdb" | ||||
| 	"github.com/containous/traefik/provider/consul" | ||||
| 	"github.com/containous/traefik/provider/consulcatalog" | ||||
| 	"github.com/containous/traefik/provider/docker" | ||||
| 	"github.com/containous/traefik/provider/dynamodb" | ||||
| 	"github.com/containous/traefik/provider/ecs" | ||||
| 	"github.com/containous/traefik/provider/etcd" | ||||
| 	"github.com/containous/traefik/provider/eureka" | ||||
| 	"github.com/containous/traefik/provider/file" | ||||
| 	"github.com/containous/traefik/provider/kubernetes" | ||||
| 	"github.com/containous/traefik/provider/marathon" | ||||
| 	"github.com/containous/traefik/provider/mesos" | ||||
| 	"github.com/containous/traefik/provider/rancher" | ||||
| 	"github.com/containous/traefik/provider/rest" | ||||
| 	"github.com/containous/traefik/provider/zk" | ||||
| 	"github.com/containous/traefik/tls" | ||||
| 	"github.com/containous/traefik/types" | ||||
| ) | ||||
|  | ||||
| const ( | ||||
| 	// DefaultInternalEntryPointName the name of the default internal entry point | ||||
| 	DefaultInternalEntryPointName = "traefik" | ||||
|  | ||||
| 	// DefaultHealthCheckInterval is the default health check interval. | ||||
| 	DefaultHealthCheckInterval = 30 * time.Second | ||||
|  | ||||
| 	// DefaultDialTimeout when connecting to a backend server. | ||||
| 	DefaultDialTimeout = 30 * time.Second | ||||
|  | ||||
| 	// DefaultIdleTimeout before closing an idle connection. | ||||
| 	DefaultIdleTimeout = 180 * time.Second | ||||
|  | ||||
| 	// DefaultGraceTimeout controls how long Traefik serves pending requests | ||||
| 	// prior to shutting down. | ||||
| 	DefaultGraceTimeout = 10 * time.Second | ||||
| ) | ||||
|  | ||||
| // GlobalConfiguration holds global configuration (with providers, etc.). | ||||
| // It's populated from the traefik configuration file passed as an argument to the binary. | ||||
| type GlobalConfiguration struct { | ||||
| 	LifeCycle                 *LifeCycle              `description:"Timeouts influencing the server life cycle" export:"true"` | ||||
| 	GraceTimeOut              flaeg.Duration          `short:"g" description:"(Deprecated) Duration to give active requests a chance to finish before Traefik stops" export:"true"` // Deprecated | ||||
| 	Debug                     bool                    `short:"d" description:"Enable debug mode" export:"true"` | ||||
| 	CheckNewVersion           bool                    `description:"Periodically check if a new version has been released" export:"true"` | ||||
| 	SendAnonymousUsage        bool                    `description:"send periodically anonymous usage statistics" export:"true"` | ||||
| 	AccessLogsFile            string                  `description:"(Deprecated) Access logs file" export:"true"` // Deprecated | ||||
| 	AccessLog                 *types.AccessLog        `description:"Access log settings" export:"true"` | ||||
| 	TraefikLogsFile           string                  `description:"(Deprecated) Traefik logs file. Stdout is used when omitted or empty" export:"true"` // Deprecated | ||||
| 	TraefikLog                *types.TraefikLog       `description:"Traefik log settings" export:"true"` | ||||
| 	Tracing                   *tracing.Tracing        `description:"OpenTracing configuration" export:"true"` | ||||
| 	LogLevel                  string                  `short:"l" description:"Log level" export:"true"` | ||||
| 	EntryPoints               EntryPoints             `description:"Entrypoints definition using format: --entryPoints='Name:http Address::8000 Redirect.EntryPoint:https' --entryPoints='Name:https Address::4442 TLS:tests/traefik.crt,tests/traefik.key;prod/traefik.crt,prod/traefik.key'" export:"true"` | ||||
| 	Cluster                   *types.Cluster          `description:"Enable clustering" export:"true"` | ||||
| 	Constraints               types.Constraints       `description:"Filter services by constraint, matching with service tags" export:"true"` | ||||
| 	ACME                      *acme.ACME              `description:"Enable ACME (Let's Encrypt): automatic SSL" export:"true"` | ||||
| 	DefaultEntryPoints        DefaultEntryPoints      `description:"Entrypoints to be used by frontends that do not specify any entrypoint" export:"true"` | ||||
| 	ProvidersThrottleDuration flaeg.Duration          `description:"Backends throttle duration: minimum duration between 2 events from providers before applying a new configuration. It avoids unnecessary reloads if multiples events are sent in a short amount of time." export:"true"` | ||||
| 	MaxIdleConnsPerHost       int                     `description:"If non-zero, controls the maximum idle (keep-alive) to keep per-host.  If zero, DefaultMaxIdleConnsPerHost is used" export:"true"` | ||||
| 	IdleTimeout               flaeg.Duration          `description:"(Deprecated) maximum amount of time an idle (keep-alive) connection will remain idle before closing itself." export:"true"` // Deprecated | ||||
| 	InsecureSkipVerify        bool                    `description:"Disable SSL certificate verification" export:"true"` | ||||
| 	RootCAs                   tls.RootCAs             `description:"Add cert file for self-signed certificate"` | ||||
| 	Retry                     *Retry                  `description:"Enable retry sending request if network error" export:"true"` | ||||
| 	HealthCheck               *HealthCheckConfig      `description:"Health check parameters" export:"true"` | ||||
| 	RespondingTimeouts        *RespondingTimeouts     `description:"Timeouts for incoming requests to the Traefik instance" export:"true"` | ||||
| 	ForwardingTimeouts        *ForwardingTimeouts     `description:"Timeouts for requests forwarded to the backend servers" export:"true"` | ||||
| 	Web                       *WebCompatibility       `description:"(Deprecated) Enable Web backend with default settings" export:"true"` // Deprecated | ||||
| 	Docker                    *docker.Provider        `description:"Enable Docker backend with default settings" export:"true"` | ||||
| 	File                      *file.Provider          `description:"Enable File backend with default settings" export:"true"` | ||||
| 	Marathon                  *marathon.Provider      `description:"Enable Marathon backend with default settings" export:"true"` | ||||
| 	Consul                    *consul.Provider        `description:"Enable Consul backend with default settings" export:"true"` | ||||
| 	ConsulCatalog             *consulcatalog.Provider `description:"Enable Consul catalog backend with default settings" export:"true"` | ||||
| 	Etcd                      *etcd.Provider          `description:"Enable Etcd backend with default settings" export:"true"` | ||||
| 	Zookeeper                 *zk.Provider            `description:"Enable Zookeeper backend with default settings" export:"true"` | ||||
| 	Boltdb                    *boltdb.Provider        `description:"Enable Boltdb backend with default settings" export:"true"` | ||||
| 	Kubernetes                *kubernetes.Provider    `description:"Enable Kubernetes backend with default settings" export:"true"` | ||||
| 	Mesos                     *mesos.Provider         `description:"Enable Mesos backend with default settings" export:"true"` | ||||
| 	Eureka                    *eureka.Provider        `description:"Enable Eureka backend with default settings" export:"true"` | ||||
| 	ECS                       *ecs.Provider           `description:"Enable ECS backend with default settings" export:"true"` | ||||
| 	Rancher                   *rancher.Provider       `description:"Enable Rancher backend with default settings" export:"true"` | ||||
| 	DynamoDB                  *dynamodb.Provider      `description:"Enable DynamoDB backend with default settings" export:"true"` | ||||
| 	ServiceFabric             *servicefabric.Provider `description:"Enable Service Fabric backend with default settings" export:"true"` | ||||
| 	Rest                      *rest.Provider          `description:"Enable Rest backend with default settings" export:"true"` | ||||
| 	API                       *api.Handler            `description:"Enable api/dashboard" export:"true"` | ||||
| 	Metrics                   *types.Metrics          `description:"Enable a metrics exporter" export:"true"` | ||||
| 	Ping                      *ping.Handler           `description:"Enable ping" export:"true"` | ||||
| } | ||||
|  | ||||
| // WebCompatibility is a configuration to handle compatibility with deprecated web provider options | ||||
| type WebCompatibility struct { | ||||
| 	Address    string            `description:"Web administration port" export:"true"` | ||||
| 	CertFile   string            `description:"SSL certificate" export:"true"` | ||||
| 	KeyFile    string            `description:"SSL certificate" export:"true"` | ||||
| 	ReadOnly   bool              `description:"Enable read only API" export:"true"` | ||||
| 	Statistics *types.Statistics `description:"Enable more detailed statistics" export:"true"` | ||||
| 	Metrics    *types.Metrics    `description:"Enable a metrics exporter" export:"true"` | ||||
| 	Path       string            `description:"Root path for dashboard and API" export:"true"` | ||||
| 	Auth       *types.Auth       `export:"true"` | ||||
| 	Debug      bool              `export:"true"` | ||||
| } | ||||
|  | ||||
| func (gc *GlobalConfiguration) handleWebDeprecation() { | ||||
| 	if gc.Web != nil { | ||||
| 		log.Warn("web provider configuration is deprecated, you should use these options : api, rest provider, ping and metrics") | ||||
|  | ||||
| 		if gc.API != nil || gc.Metrics != nil || gc.Ping != nil || gc.Rest != nil { | ||||
| 			log.Warn("web option is ignored if you use it with one of these options : api, rest provider, ping or metrics") | ||||
| 			return | ||||
| 		} | ||||
| 		gc.EntryPoints[DefaultInternalEntryPointName] = &EntryPoint{ | ||||
| 			Address: gc.Web.Address, | ||||
| 			Auth:    gc.Web.Auth, | ||||
| 		} | ||||
| 		if gc.Web.CertFile != "" { | ||||
| 			gc.EntryPoints[DefaultInternalEntryPointName].TLS = &tls.TLS{ | ||||
| 				Certificates: []tls.Certificate{ | ||||
| 					{ | ||||
| 						CertFile: tls.FileOrContent(gc.Web.CertFile), | ||||
| 						KeyFile:  tls.FileOrContent(gc.Web.KeyFile), | ||||
| 					}, | ||||
| 				}, | ||||
| 			} | ||||
| 		} | ||||
|  | ||||
| 		if gc.API == nil { | ||||
| 			gc.API = &api.Handler{ | ||||
| 				EntryPoint: DefaultInternalEntryPointName, | ||||
| 				Statistics: gc.Web.Statistics, | ||||
| 				Dashboard:  true, | ||||
| 			} | ||||
| 		} | ||||
|  | ||||
| 		if gc.Ping == nil { | ||||
| 			gc.Ping = &ping.Handler{ | ||||
| 				EntryPoint: DefaultInternalEntryPointName, | ||||
| 			} | ||||
| 		} | ||||
|  | ||||
| 		if gc.Metrics == nil { | ||||
| 			gc.Metrics = gc.Web.Metrics | ||||
| 		} | ||||
|  | ||||
| 		if !gc.Debug { | ||||
| 			gc.Debug = gc.Web.Debug | ||||
| 		} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // SetEffectiveConfiguration adds missing configuration parameters derived from existing ones. | ||||
| // It also takes care of maintaining backwards compatibility. | ||||
| func (gc *GlobalConfiguration) SetEffectiveConfiguration(configFile string) { | ||||
| 	if len(gc.EntryPoints) == 0 { | ||||
| 		gc.EntryPoints = map[string]*EntryPoint{"http": { | ||||
| 			Address:          ":80", | ||||
| 			ForwardedHeaders: &ForwardedHeaders{Insecure: true}, | ||||
| 		}} | ||||
| 		gc.DefaultEntryPoints = []string{"http"} | ||||
| 	} | ||||
|  | ||||
| 	gc.handleWebDeprecation() | ||||
|  | ||||
| 	if (gc.API != nil && gc.API.EntryPoint == DefaultInternalEntryPointName) || | ||||
| 		(gc.Ping != nil && gc.Ping.EntryPoint == DefaultInternalEntryPointName) || | ||||
| 		(gc.Metrics != nil && gc.Metrics.Prometheus != nil && gc.Metrics.Prometheus.EntryPoint == DefaultInternalEntryPointName) || | ||||
| 		(gc.Rest != nil && gc.Rest.EntryPoint == DefaultInternalEntryPointName) { | ||||
| 		if _, ok := gc.EntryPoints[DefaultInternalEntryPointName]; !ok { | ||||
| 			gc.EntryPoints[DefaultInternalEntryPointName] = &EntryPoint{Address: ":8080"} | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	for entryPointName := range gc.EntryPoints { | ||||
| 		entryPoint := gc.EntryPoints[entryPointName] | ||||
| 		// ForwardedHeaders must be remove in the next breaking version | ||||
| 		if entryPoint.ForwardedHeaders == nil { | ||||
| 			entryPoint.ForwardedHeaders = &ForwardedHeaders{Insecure: true} | ||||
| 		} | ||||
|  | ||||
| 		if len(entryPoint.WhitelistSourceRange) > 0 { | ||||
| 			log.Warnf("Deprecated configuration found: %s. Please use %s.", "whiteListSourceRange", "whiteList.sourceRange") | ||||
|  | ||||
| 			if entryPoint.WhiteList == nil { | ||||
| 				entryPoint.WhiteList = &types.WhiteList{ | ||||
| 					SourceRange: entryPoint.WhitelistSourceRange, | ||||
| 				} | ||||
| 				entryPoint.WhitelistSourceRange = nil | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	// Make sure LifeCycle isn't nil to spare nil checks elsewhere. | ||||
| 	if gc.LifeCycle == nil { | ||||
| 		gc.LifeCycle = &LifeCycle{} | ||||
| 	} | ||||
|  | ||||
| 	// Prefer legacy grace timeout parameter for backwards compatibility reasons. | ||||
| 	if gc.GraceTimeOut > 0 { | ||||
| 		log.Warn("top-level grace period configuration has been deprecated -- please use lifecycle grace period") | ||||
| 		gc.LifeCycle.GraceTimeOut = gc.GraceTimeOut | ||||
| 	} | ||||
|  | ||||
| 	if gc.Docker != nil { | ||||
| 		if len(gc.Docker.Filename) != 0 && gc.Docker.TemplateVersion != 2 { | ||||
| 			log.Warn("Template version 1 is deprecated, please use version 2, see TemplateVersion.") | ||||
| 			gc.Docker.TemplateVersion = 1 | ||||
| 		} else { | ||||
| 			gc.Docker.TemplateVersion = 2 | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if gc.Marathon != nil { | ||||
| 		if len(gc.Marathon.Filename) != 0 && gc.Marathon.TemplateVersion != 2 { | ||||
| 			log.Warn("Template version 1 is deprecated, please use version 2, see TemplateVersion.") | ||||
| 			gc.Marathon.TemplateVersion = 1 | ||||
| 		} else { | ||||
| 			gc.Marathon.TemplateVersion = 2 | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if gc.Eureka != nil { | ||||
| 		if gc.Eureka.Delay != 0 { | ||||
| 			log.Warn("Delay has been deprecated -- please use RefreshSeconds") | ||||
| 			gc.Eureka.RefreshSeconds = gc.Eureka.Delay | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if gc.Rancher != nil { | ||||
| 		if len(gc.Rancher.Filename) != 0 && gc.Rancher.TemplateVersion != 2 { | ||||
| 			log.Warn("Template version 1 is deprecated, please use version 2, see TemplateVersion.") | ||||
| 			gc.Rancher.TemplateVersion = 1 | ||||
| 		} else { | ||||
| 			gc.Rancher.TemplateVersion = 2 | ||||
| 		} | ||||
|  | ||||
| 		// Ensure backwards compatibility for now | ||||
| 		if len(gc.Rancher.AccessKey) > 0 || | ||||
| 			len(gc.Rancher.Endpoint) > 0 || | ||||
| 			len(gc.Rancher.SecretKey) > 0 { | ||||
|  | ||||
| 			if gc.Rancher.API == nil { | ||||
| 				gc.Rancher.API = &rancher.APIConfiguration{ | ||||
| 					AccessKey: gc.Rancher.AccessKey, | ||||
| 					SecretKey: gc.Rancher.SecretKey, | ||||
| 					Endpoint:  gc.Rancher.Endpoint, | ||||
| 				} | ||||
| 			} | ||||
| 			log.Warn("Deprecated configuration found: rancher.[accesskey|secretkey|endpoint]. " + | ||||
| 				"Please use rancher.api.[accesskey|secretkey|endpoint] instead.") | ||||
| 		} | ||||
|  | ||||
| 		if gc.Rancher.Metadata != nil && len(gc.Rancher.Metadata.Prefix) == 0 { | ||||
| 			gc.Rancher.Metadata.Prefix = "latest" | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if gc.API != nil { | ||||
| 		gc.API.Debug = gc.Debug | ||||
| 	} | ||||
|  | ||||
| 	if gc.Web != nil && (gc.Web.Path == "" || !strings.HasSuffix(gc.Web.Path, "/")) { | ||||
| 		gc.Web.Path += "/" | ||||
| 	} | ||||
|  | ||||
| 	// Try to fallback to traefik config file in case the file provider is enabled | ||||
| 	// but has no file name configured and is not in a directory mode. | ||||
| 	if gc.File != nil && len(gc.File.Filename) == 0 && len(gc.File.Directory) == 0 { | ||||
| 		if len(configFile) > 0 { | ||||
| 			gc.File.Filename = configFile | ||||
| 		} else { | ||||
| 			log.Errorln("Error using file configuration backend, no filename defined") | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	gc.initACMEProvider() | ||||
| } | ||||
|  | ||||
| func (gc *GlobalConfiguration) initACMEProvider() { | ||||
| 	if gc.ACME != nil { | ||||
| 		// TODO: to remove in the futurs | ||||
| 		if len(gc.ACME.StorageFile) > 0 && len(gc.ACME.Storage) == 0 { | ||||
| 			log.Warn("ACME.StorageFile is deprecated, use ACME.Storage instead") | ||||
| 			gc.ACME.Storage = gc.ACME.StorageFile | ||||
| 		} | ||||
|  | ||||
| 		if len(gc.ACME.DNSProvider) > 0 { | ||||
| 			log.Warn("ACME.DNSProvider is deprecated, use ACME.DNSChallenge instead") | ||||
| 			gc.ACME.DNSChallenge = &acmeprovider.DNSChallenge{Provider: gc.ACME.DNSProvider, DelayBeforeCheck: gc.ACME.DelayDontCheckDNS} | ||||
| 		} | ||||
|  | ||||
| 		if gc.ACME.OnDemand { | ||||
| 			log.Warn("ACME.OnDemand is deprecated") | ||||
| 		} | ||||
|  | ||||
| 		// TODO: Remove when Provider ACME will replace totally ACME | ||||
| 		// If provider file, use Provider ACME instead of ACME | ||||
| 		if gc.Cluster == nil { | ||||
| 			acmeprovider.Get().Configuration = &acmeprovider.Configuration{ | ||||
| 				OnHostRule:    gc.ACME.OnHostRule, | ||||
| 				OnDemand:      gc.ACME.OnDemand, | ||||
| 				Email:         gc.ACME.Email, | ||||
| 				Storage:       gc.ACME.Storage, | ||||
| 				HTTPChallenge: gc.ACME.HTTPChallenge, | ||||
| 				DNSChallenge:  gc.ACME.DNSChallenge, | ||||
| 				Domains:       gc.ACME.Domains, | ||||
| 				ACMELogging:   gc.ACME.ACMELogging, | ||||
| 				CAServer:      gc.ACME.CAServer, | ||||
| 				EntryPoint:    gc.ACME.EntryPoint, | ||||
| 			} | ||||
| 			gc.ACME = nil | ||||
| 		} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // ValidateConfiguration validate that configuration is coherent | ||||
| func (gc *GlobalConfiguration) ValidateConfiguration() { | ||||
| 	if gc.ACME != nil { | ||||
| 		if _, ok := gc.EntryPoints[gc.ACME.EntryPoint]; !ok { | ||||
| 			log.Fatalf("Unknown entrypoint %q for ACME configuration", gc.ACME.EntryPoint) | ||||
| 		} else { | ||||
| 			if gc.EntryPoints[gc.ACME.EntryPoint].TLS == nil { | ||||
| 				log.Fatalf("Entrypoint %q has no TLS configuration for ACME configuration", gc.ACME.EntryPoint) | ||||
| 			} | ||||
| 		} | ||||
| 	} else if acmeprovider.IsEnabled() { | ||||
| 		if _, ok := gc.EntryPoints[acmeprovider.Get().EntryPoint]; !ok { | ||||
| 			log.Fatalf("Unknown entrypoint %q for provider ACME configuration", acmeprovider.Get().EntryPoint) | ||||
| 		} else { | ||||
| 			if gc.EntryPoints[acmeprovider.Get().EntryPoint].TLS == nil { | ||||
| 				log.Fatalf("Entrypoint %q has no TLS configuration for provider ACME configuration", acmeprovider.Get().EntryPoint) | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| // DefaultEntryPoints holds default entry points | ||||
| type DefaultEntryPoints []string | ||||
|  | ||||
| // String is the method to format the flag's value, part of the flag.Value interface. | ||||
| // The String method's output will be used in diagnostics. | ||||
| func (dep *DefaultEntryPoints) String() string { | ||||
| 	return strings.Join(*dep, ",") | ||||
| } | ||||
|  | ||||
| // Set is the method to set the flag value, part of the flag.Value interface. | ||||
| // Set's argument is a string to be parsed to set the flag. | ||||
| // It's a comma-separated list, so we split it. | ||||
| func (dep *DefaultEntryPoints) Set(value string) error { | ||||
| 	entrypoints := strings.Split(value, ",") | ||||
| 	if len(entrypoints) == 0 { | ||||
| 		return fmt.Errorf("bad DefaultEntryPoints format: %s", value) | ||||
| 	} | ||||
| 	for _, entrypoint := range entrypoints { | ||||
| 		*dep = append(*dep, entrypoint) | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| // Get return the EntryPoints map | ||||
| func (dep *DefaultEntryPoints) Get() interface{} { | ||||
| 	return *dep | ||||
| } | ||||
|  | ||||
| // SetValue sets the EntryPoints map with val | ||||
| func (dep *DefaultEntryPoints) SetValue(val interface{}) { | ||||
| 	*dep = val.(DefaultEntryPoints) | ||||
| } | ||||
|  | ||||
| // Type is type of the struct | ||||
| func (dep *DefaultEntryPoints) Type() string { | ||||
| 	return "defaultentrypoints" | ||||
| } | ||||
|  | ||||
| // Retry contains request retry config | ||||
| type Retry struct { | ||||
| 	Attempts int `description:"Number of attempts" export:"true"` | ||||
| } | ||||
|  | ||||
| // HealthCheckConfig contains health check configuration parameters. | ||||
| type HealthCheckConfig struct { | ||||
| 	Interval flaeg.Duration `description:"Default periodicity of enabled health checks" export:"true"` | ||||
| } | ||||
|  | ||||
| // RespondingTimeouts contains timeout configurations for incoming requests to the Traefik instance. | ||||
| type RespondingTimeouts struct { | ||||
| 	ReadTimeout  flaeg.Duration `description:"ReadTimeout is the maximum duration for reading the entire request, including the body. If zero, no timeout is set" export:"true"` | ||||
| 	WriteTimeout flaeg.Duration `description:"WriteTimeout is the maximum duration before timing out writes of the response. If zero, no timeout is set" export:"true"` | ||||
| 	IdleTimeout  flaeg.Duration `description:"IdleTimeout is the maximum amount duration an idle (keep-alive) connection will remain idle before closing itself. Defaults to 180 seconds. If zero, no timeout is set" export:"true"` | ||||
| } | ||||
|  | ||||
| // ForwardingTimeouts contains timeout configurations for forwarding requests to the backend servers. | ||||
| type ForwardingTimeouts struct { | ||||
| 	DialTimeout           flaeg.Duration `description:"The amount of time to wait until a connection to a backend server can be established. Defaults to 30 seconds. If zero, no timeout exists" export:"true"` | ||||
| 	ResponseHeaderTimeout flaeg.Duration `description:"The amount of time to wait for a server's response headers after fully writing the request (including its body, if any). If zero, no timeout exists" export:"true"` | ||||
| } | ||||
|  | ||||
| // LifeCycle contains configurations relevant to the lifecycle (such as the | ||||
| // shutdown phase) of Traefik. | ||||
| type LifeCycle struct { | ||||
| 	RequestAcceptGraceTimeout flaeg.Duration `description:"Duration to keep accepting requests before Traefik initiates the graceful shutdown procedure"` | ||||
| 	GraceTimeOut              flaeg.Duration `description:"Duration to give active requests a chance to finish before Traefik stops"` | ||||
| } | ||||
| @@ -1,103 +0,0 @@ | ||||
| package configuration | ||||
|  | ||||
| import ( | ||||
| 	"testing" | ||||
| 	"time" | ||||
|  | ||||
| 	"github.com/containous/flaeg" | ||||
| 	"github.com/containous/traefik/provider" | ||||
| 	"github.com/containous/traefik/provider/file" | ||||
| ) | ||||
|  | ||||
| const defaultConfigFile = "traefik.toml" | ||||
|  | ||||
| func TestSetEffectiveConfigurationGraceTimeout(t *testing.T) { | ||||
| 	tests := []struct { | ||||
| 		desc                  string | ||||
| 		legacyGraceTimeout    time.Duration | ||||
| 		lifeCycleGraceTimeout time.Duration | ||||
| 		wantGraceTimeout      time.Duration | ||||
| 	}{ | ||||
| 		{ | ||||
| 			desc:               "legacy grace timeout given only", | ||||
| 			legacyGraceTimeout: 5 * time.Second, | ||||
| 			wantGraceTimeout:   5 * time.Second, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:                  "legacy and life cycle grace timeouts given", | ||||
| 			legacyGraceTimeout:    5 * time.Second, | ||||
| 			lifeCycleGraceTimeout: 12 * time.Second, | ||||
| 			wantGraceTimeout:      5 * time.Second, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:                  "legacy grace timeout omitted", | ||||
| 			legacyGraceTimeout:    0, | ||||
| 			lifeCycleGraceTimeout: 12 * time.Second, | ||||
| 			wantGraceTimeout:      12 * time.Second, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range tests { | ||||
| 		test := test | ||||
| 		t.Run(test.desc, func(t *testing.T) { | ||||
| 			t.Parallel() | ||||
| 			gc := &GlobalConfiguration{ | ||||
| 				GraceTimeOut: flaeg.Duration(test.legacyGraceTimeout), | ||||
| 			} | ||||
| 			if test.lifeCycleGraceTimeout > 0 { | ||||
| 				gc.LifeCycle = &LifeCycle{ | ||||
| 					GraceTimeOut: flaeg.Duration(test.lifeCycleGraceTimeout), | ||||
| 				} | ||||
| 			} | ||||
|  | ||||
| 			gc.SetEffectiveConfiguration(defaultConfigFile) | ||||
|  | ||||
| 			gotGraceTimeout := time.Duration(gc.LifeCycle.GraceTimeOut) | ||||
| 			if gotGraceTimeout != test.wantGraceTimeout { | ||||
| 				t.Fatalf("got effective grace timeout %d, want %d", gotGraceTimeout, test.wantGraceTimeout) | ||||
| 			} | ||||
|  | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestSetEffectiveConfigurationFileProviderFilename(t *testing.T) { | ||||
| 	tests := []struct { | ||||
| 		desc                     string | ||||
| 		fileProvider             *file.Provider | ||||
| 		wantFileProviderFilename string | ||||
| 	}{ | ||||
| 		{ | ||||
| 			desc:                     "no filename for file provider given", | ||||
| 			fileProvider:             &file.Provider{}, | ||||
| 			wantFileProviderFilename: defaultConfigFile, | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:                     "filename for file provider given", | ||||
| 			fileProvider:             &file.Provider{BaseProvider: provider.BaseProvider{Filename: "other.toml"}}, | ||||
| 			wantFileProviderFilename: "other.toml", | ||||
| 		}, | ||||
| 		{ | ||||
| 			desc:                     "directory for file provider given", | ||||
| 			fileProvider:             &file.Provider{Directory: "/"}, | ||||
| 			wantFileProviderFilename: "", | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range tests { | ||||
| 		test := test | ||||
| 		t.Run(test.desc, func(t *testing.T) { | ||||
| 			t.Parallel() | ||||
| 			gc := &GlobalConfiguration{ | ||||
| 				File: test.fileProvider, | ||||
| 			} | ||||
|  | ||||
| 			gc.SetEffectiveConfiguration(defaultConfigFile) | ||||
|  | ||||
| 			gotFileProviderFilename := gc.File.Filename | ||||
| 			if gotFileProviderFilename != test.wantFileProviderFilename { | ||||
| 				t.Fatalf("got file provider file name %q, want %q", gotFileProviderFilename, test.wantFileProviderFilename) | ||||
| 			} | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
| @@ -1,266 +0,0 @@ | ||||
| package configuration | ||||
|  | ||||
| import ( | ||||
| 	"fmt" | ||||
| 	"strings" | ||||
|  | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/tls" | ||||
| 	"github.com/containous/traefik/types" | ||||
| ) | ||||
|  | ||||
| // EntryPoint holds an entry point configuration of the reverse proxy (ip, port, TLS...) | ||||
| type EntryPoint struct { | ||||
| 	Address              string | ||||
| 	TLS                  *tls.TLS          `export:"true"` | ||||
| 	Redirect             *types.Redirect   `export:"true"` | ||||
| 	Auth                 *types.Auth       `export:"true"` | ||||
| 	WhitelistSourceRange []string          // Deprecated | ||||
| 	WhiteList            *types.WhiteList  `export:"true"` | ||||
| 	Compress             bool              `export:"true"` | ||||
| 	ProxyProtocol        *ProxyProtocol    `export:"true"` | ||||
| 	ForwardedHeaders     *ForwardedHeaders `export:"true"` | ||||
| } | ||||
|  | ||||
| // ProxyProtocol contains Proxy-Protocol configuration | ||||
| type ProxyProtocol struct { | ||||
| 	Insecure   bool `export:"true"` | ||||
| 	TrustedIPs []string | ||||
| } | ||||
|  | ||||
| // ForwardedHeaders Trust client forwarding headers | ||||
| type ForwardedHeaders struct { | ||||
| 	Insecure   bool `export:"true"` | ||||
| 	TrustedIPs []string | ||||
| } | ||||
|  | ||||
| // EntryPoints holds entry points configuration of the reverse proxy (ip, port, TLS...) | ||||
| type EntryPoints map[string]*EntryPoint | ||||
|  | ||||
| // String is the method to format the flag's value, part of the flag.Value interface. | ||||
| // The String method's output will be used in diagnostics. | ||||
| func (ep EntryPoints) String() string { | ||||
| 	return fmt.Sprintf("%+v", map[string]*EntryPoint(ep)) | ||||
| } | ||||
|  | ||||
| // Get return the EntryPoints map | ||||
| func (ep *EntryPoints) Get() interface{} { | ||||
| 	return *ep | ||||
| } | ||||
|  | ||||
| // SetValue sets the EntryPoints map with val | ||||
| func (ep *EntryPoints) SetValue(val interface{}) { | ||||
| 	*ep = val.(EntryPoints) | ||||
| } | ||||
|  | ||||
| // Type is type of the struct | ||||
| func (ep *EntryPoints) Type() string { | ||||
| 	return "entrypoints" | ||||
| } | ||||
|  | ||||
| // Set is the method to set the flag value, part of the flag.Value interface. | ||||
| // Set's argument is a string to be parsed to set the flag. | ||||
| // It's a comma-separated list, so we split it. | ||||
| func (ep *EntryPoints) Set(value string) error { | ||||
| 	result := parseEntryPointsConfiguration(value) | ||||
|  | ||||
| 	var whiteListSourceRange []string | ||||
| 	if len(result["whitelistsourcerange"]) > 0 { | ||||
| 		whiteListSourceRange = strings.Split(result["whitelistsourcerange"], ",") | ||||
| 	} | ||||
|  | ||||
| 	compress := toBool(result, "compress") | ||||
|  | ||||
| 	configTLS, err := makeEntryPointTLS(result) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	(*ep)[result["name"]] = &EntryPoint{ | ||||
| 		Address:              result["address"], | ||||
| 		TLS:                  configTLS, | ||||
| 		Auth:                 makeEntryPointAuth(result), | ||||
| 		Redirect:             makeEntryPointRedirect(result), | ||||
| 		Compress:             compress, | ||||
| 		WhitelistSourceRange: whiteListSourceRange, | ||||
| 		WhiteList:            makeWhiteList(result), | ||||
| 		ProxyProtocol:        makeEntryPointProxyProtocol(result), | ||||
| 		ForwardedHeaders:     makeEntryPointForwardedHeaders(result), | ||||
| 	} | ||||
|  | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func makeWhiteList(result map[string]string) *types.WhiteList { | ||||
| 	var wl *types.WhiteList | ||||
| 	if rawRange, ok := result["whitelist_sourcerange"]; ok { | ||||
| 		wl = &types.WhiteList{ | ||||
| 			SourceRange:      strings.Split(rawRange, ","), | ||||
| 			UseXForwardedFor: toBool(result, "whitelist_usexforwardedfor"), | ||||
| 		} | ||||
| 	} | ||||
| 	return wl | ||||
| } | ||||
|  | ||||
| func makeEntryPointAuth(result map[string]string) *types.Auth { | ||||
| 	var basic *types.Basic | ||||
| 	if v, ok := result["auth_basic_users"]; ok { | ||||
| 		basic = &types.Basic{ | ||||
| 			Users: strings.Split(v, ","), | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	var digest *types.Digest | ||||
| 	if v, ok := result["auth_digest_users"]; ok { | ||||
| 		digest = &types.Digest{ | ||||
| 			Users: strings.Split(v, ","), | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	var forward *types.Forward | ||||
| 	if address, ok := result["auth_forward_address"]; ok { | ||||
| 		var clientTLS *types.ClientTLS | ||||
|  | ||||
| 		cert := result["auth_forward_tls_cert"] | ||||
| 		key := result["auth_forward_tls_key"] | ||||
| 		insecureSkipVerify := toBool(result, "auth_forward_tls_insecureskipverify") | ||||
|  | ||||
| 		if len(cert) > 0 && len(key) > 0 || insecureSkipVerify { | ||||
| 			clientTLS = &types.ClientTLS{ | ||||
| 				CA:                 result["auth_forward_tls_ca"], | ||||
| 				CAOptional:         toBool(result, "auth_forward_tls_caoptional"), | ||||
| 				Cert:               cert, | ||||
| 				Key:                key, | ||||
| 				InsecureSkipVerify: insecureSkipVerify, | ||||
| 			} | ||||
| 		} | ||||
|  | ||||
| 		forward = &types.Forward{ | ||||
| 			Address:            address, | ||||
| 			TLS:                clientTLS, | ||||
| 			TrustForwardHeader: toBool(result, "auth_forward_trustforwardheader"), | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	var auth *types.Auth | ||||
| 	if basic != nil || digest != nil || forward != nil { | ||||
| 		auth = &types.Auth{ | ||||
| 			Basic:       basic, | ||||
| 			Digest:      digest, | ||||
| 			Forward:     forward, | ||||
| 			HeaderField: result["auth_headerfield"], | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return auth | ||||
| } | ||||
|  | ||||
| func makeEntryPointProxyProtocol(result map[string]string) *ProxyProtocol { | ||||
| 	var proxyProtocol *ProxyProtocol | ||||
|  | ||||
| 	ppTrustedIPs := result["proxyprotocol_trustedips"] | ||||
| 	if len(result["proxyprotocol_insecure"]) > 0 || len(ppTrustedIPs) > 0 { | ||||
| 		proxyProtocol = &ProxyProtocol{ | ||||
| 			Insecure: toBool(result, "proxyprotocol_insecure"), | ||||
| 		} | ||||
| 		if len(ppTrustedIPs) > 0 { | ||||
| 			proxyProtocol.TrustedIPs = strings.Split(ppTrustedIPs, ",") | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if proxyProtocol != nil && proxyProtocol.Insecure { | ||||
| 		log.Warn("ProxyProtocol.Insecure:true is dangerous. Please use 'ProxyProtocol.TrustedIPs:IPs' and remove 'ProxyProtocol.Insecure:true'") | ||||
| 	} | ||||
|  | ||||
| 	return proxyProtocol | ||||
| } | ||||
|  | ||||
| func makeEntryPointForwardedHeaders(result map[string]string) *ForwardedHeaders { | ||||
| 	// TODO must be changed to false by default in the next breaking version. | ||||
| 	forwardedHeaders := &ForwardedHeaders{Insecure: true} | ||||
| 	if _, ok := result["forwardedheaders_insecure"]; ok { | ||||
| 		forwardedHeaders.Insecure = toBool(result, "forwardedheaders_insecure") | ||||
| 	} | ||||
|  | ||||
| 	fhTrustedIPs := result["forwardedheaders_trustedips"] | ||||
| 	if len(fhTrustedIPs) > 0 { | ||||
| 		// TODO must be removed in the next breaking version. | ||||
| 		forwardedHeaders.Insecure = toBool(result, "forwardedheaders_insecure") | ||||
| 		forwardedHeaders.TrustedIPs = strings.Split(fhTrustedIPs, ",") | ||||
| 	} | ||||
|  | ||||
| 	return forwardedHeaders | ||||
| } | ||||
|  | ||||
| func makeEntryPointRedirect(result map[string]string) *types.Redirect { | ||||
| 	var redirect *types.Redirect | ||||
|  | ||||
| 	if len(result["redirect_entrypoint"]) > 0 || len(result["redirect_regex"]) > 0 || len(result["redirect_replacement"]) > 0 { | ||||
| 		redirect = &types.Redirect{ | ||||
| 			EntryPoint:  result["redirect_entrypoint"], | ||||
| 			Regex:       result["redirect_regex"], | ||||
| 			Replacement: result["redirect_replacement"], | ||||
| 			Permanent:   toBool(result, "redirect_permanent"), | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return redirect | ||||
| } | ||||
|  | ||||
| func makeEntryPointTLS(result map[string]string) (*tls.TLS, error) { | ||||
| 	var configTLS *tls.TLS | ||||
|  | ||||
| 	if len(result["tls"]) > 0 { | ||||
| 		certs := tls.Certificates{} | ||||
| 		if err := certs.Set(result["tls"]); err != nil { | ||||
| 			return nil, err | ||||
| 		} | ||||
| 		configTLS = &tls.TLS{ | ||||
| 			Certificates: certs, | ||||
| 		} | ||||
| 	} else if len(result["tls_acme"]) > 0 { | ||||
| 		configTLS = &tls.TLS{ | ||||
| 			Certificates: tls.Certificates{}, | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	if len(result["ca"]) > 0 { | ||||
| 		files := strings.Split(result["ca"], ",") | ||||
| 		optional := toBool(result, "ca_optional") | ||||
| 		configTLS.ClientCA = tls.ClientCA{ | ||||
| 			Files:    files, | ||||
| 			Optional: optional, | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return configTLS, nil | ||||
| } | ||||
|  | ||||
| func parseEntryPointsConfiguration(raw string) map[string]string { | ||||
| 	sections := strings.Fields(raw) | ||||
|  | ||||
| 	config := make(map[string]string) | ||||
| 	for _, part := range sections { | ||||
| 		field := strings.SplitN(part, ":", 2) | ||||
| 		name := strings.ToLower(strings.Replace(field[0], ".", "_", -1)) | ||||
| 		if len(field) > 1 { | ||||
| 			config[name] = field[1] | ||||
| 		} else { | ||||
| 			if strings.EqualFold(name, "TLS") { | ||||
| 				config["tls_acme"] = "TLS" | ||||
| 			} else { | ||||
| 				config[name] = "" | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| 	return config | ||||
| } | ||||
|  | ||||
| func toBool(conf map[string]string, key string) bool { | ||||
| 	if val, ok := conf[key]; ok { | ||||
| 		return strings.EqualFold(val, "true") || | ||||
| 			strings.EqualFold(val, "enable") || | ||||
| 			strings.EqualFold(val, "on") | ||||
| 	} | ||||
| 	return false | ||||
| } | ||||
| @@ -1,459 +0,0 @@ | ||||
| package configuration | ||||
|  | ||||
| import ( | ||||
| 	"testing" | ||||
|  | ||||
| 	"github.com/containous/traefik/tls" | ||||
| 	"github.com/containous/traefik/types" | ||||
| 	"github.com/stretchr/testify/assert" | ||||
| 	"github.com/stretchr/testify/require" | ||||
| ) | ||||
|  | ||||
| func Test_parseEntryPointsConfiguration(t *testing.T) { | ||||
| 	testCases := []struct { | ||||
| 		name           string | ||||
| 		value          string | ||||
| 		expectedResult map[string]string | ||||
| 	}{ | ||||
| 		{ | ||||
| 			name: "all parameters", | ||||
| 			value: "Name:foo " + | ||||
| 				"Address::8000 " + | ||||
| 				"TLS:goo,gii " + | ||||
| 				"TLS " + | ||||
| 				"CA:car " + | ||||
| 				"CA.Optional:true " + | ||||
| 				"Redirect.EntryPoint:https " + | ||||
| 				"Redirect.Regex:http://localhost/(.*) " + | ||||
| 				"Redirect.Replacement:http://mydomain/$1 " + | ||||
| 				"Redirect.Permanent:true " + | ||||
| 				"Compress:true " + | ||||
| 				"ProxyProtocol.TrustedIPs:192.168.0.1 " + | ||||
| 				"ForwardedHeaders.TrustedIPs:10.0.0.3/24,20.0.0.3/24 " + | ||||
| 				"Auth.Basic.Users:test:$apr1$H6uskkkW$IgXLP6ewTrSuBkTrqE8wj/,test2:$apr1$d9hr9HBB$4HxwgUir3HP4EsggP/QNo0 " + | ||||
| 				"Auth.Digest.Users:test:traefik:a2688e031edb4be6a3797f3882655c05,test2:traefik:518845800f9e2bfb1f1f740ec24f074e " + | ||||
| 				"Auth.HeaderField:X-WebAuth-User " + | ||||
| 				"Auth.Forward.Address:https://authserver.com/auth " + | ||||
| 				"Auth.Forward.TrustForwardHeader:true " + | ||||
| 				"Auth.Forward.TLS.CA:path/to/local.crt " + | ||||
| 				"Auth.Forward.TLS.CAOptional:true " + | ||||
| 				"Auth.Forward.TLS.Cert:path/to/foo.cert " + | ||||
| 				"Auth.Forward.TLS.Key:path/to/foo.key " + | ||||
| 				"Auth.Forward.TLS.InsecureSkipVerify:true " + | ||||
| 				"WhiteListSourceRange:10.42.0.0/16,152.89.1.33/32,afed:be44::/16 " + | ||||
| 				"whiteList.sourceRange:10.42.0.0/16,152.89.1.33/32,afed:be44::/16 " + | ||||
| 				"whiteList.useXForwardedFor:true ", | ||||
| 			expectedResult: map[string]string{ | ||||
| 				"address":                             ":8000", | ||||
| 				"auth_basic_users":                    "test:$apr1$H6uskkkW$IgXLP6ewTrSuBkTrqE8wj/,test2:$apr1$d9hr9HBB$4HxwgUir3HP4EsggP/QNo0", | ||||
| 				"auth_digest_users":                   "test:traefik:a2688e031edb4be6a3797f3882655c05,test2:traefik:518845800f9e2bfb1f1f740ec24f074e", | ||||
| 				"auth_forward_address":                "https://authserver.com/auth", | ||||
| 				"auth_forward_tls_ca":                 "path/to/local.crt", | ||||
| 				"auth_forward_tls_caoptional":         "true", | ||||
| 				"auth_forward_tls_cert":               "path/to/foo.cert", | ||||
| 				"auth_forward_tls_insecureskipverify": "true", | ||||
| 				"auth_forward_tls_key":                "path/to/foo.key", | ||||
| 				"auth_forward_trustforwardheader":     "true", | ||||
| 				"auth_headerfield":                    "X-WebAuth-User", | ||||
| 				"ca":                                  "car", | ||||
| 				"ca_optional":                         "true", | ||||
| 				"compress":                            "true", | ||||
| 				"forwardedheaders_trustedips":         "10.0.0.3/24,20.0.0.3/24", | ||||
| 				"name": "foo", | ||||
| 				"proxyprotocol_trustedips": "192.168.0.1", | ||||
| 				"redirect_entrypoint":      "https", | ||||
| 				"redirect_permanent":       "true", | ||||
| 				"redirect_regex":           "http://localhost/(.*)", | ||||
| 				"redirect_replacement":     "http://mydomain/$1", | ||||
| 				"tls":                        "goo,gii", | ||||
| 				"tls_acme":                   "TLS", | ||||
| 				"whitelistsourcerange":       "10.42.0.0/16,152.89.1.33/32,afed:be44::/16", | ||||
| 				"whitelist_sourcerange":      "10.42.0.0/16,152.89.1.33/32,afed:be44::/16", | ||||
| 				"whitelist_usexforwardedfor": "true", | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:  "compress on", | ||||
| 			value: "name:foo Compress:on", | ||||
| 			expectedResult: map[string]string{ | ||||
| 				"name":     "foo", | ||||
| 				"compress": "on", | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:  "TLS", | ||||
| 			value: "Name:foo TLS:goo TLS", | ||||
| 			expectedResult: map[string]string{ | ||||
| 				"name":     "foo", | ||||
| 				"tls":      "goo", | ||||
| 				"tls_acme": "TLS", | ||||
| 			}, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range testCases { | ||||
| 		test := test | ||||
| 		t.Run(test.name, func(t *testing.T) { | ||||
| 			t.Parallel() | ||||
|  | ||||
| 			conf := parseEntryPointsConfiguration(test.value) | ||||
|  | ||||
| 			assert.Len(t, conf, len(test.expectedResult)) | ||||
| 			assert.Equal(t, test.expectedResult, conf) | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func Test_toBool(t *testing.T) { | ||||
| 	testCases := []struct { | ||||
| 		name         string | ||||
| 		value        string | ||||
| 		key          string | ||||
| 		expectedBool bool | ||||
| 	}{ | ||||
| 		{ | ||||
| 			name:         "on", | ||||
| 			value:        "on", | ||||
| 			key:          "foo", | ||||
| 			expectedBool: true, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:         "true", | ||||
| 			value:        "true", | ||||
| 			key:          "foo", | ||||
| 			expectedBool: true, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:         "enable", | ||||
| 			value:        "enable", | ||||
| 			key:          "foo", | ||||
| 			expectedBool: true, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:         "arbitrary string", | ||||
| 			value:        "bar", | ||||
| 			key:          "foo", | ||||
| 			expectedBool: false, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:         "no existing entry", | ||||
| 			value:        "bar", | ||||
| 			key:          "fii", | ||||
| 			expectedBool: false, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range testCases { | ||||
| 		test := test | ||||
| 		t.Run(test.name, func(t *testing.T) { | ||||
| 			t.Parallel() | ||||
|  | ||||
| 			conf := map[string]string{ | ||||
| 				"foo": test.value, | ||||
| 			} | ||||
|  | ||||
| 			result := toBool(conf, test.key) | ||||
|  | ||||
| 			assert.Equal(t, test.expectedBool, result) | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func TestEntryPoints_Set(t *testing.T) { | ||||
| 	testCases := []struct { | ||||
| 		name                   string | ||||
| 		expression             string | ||||
| 		expectedEntryPointName string | ||||
| 		expectedEntryPoint     *EntryPoint | ||||
| 	}{ | ||||
| 		{ | ||||
| 			name: "all parameters camelcase", | ||||
| 			expression: "Name:foo " + | ||||
| 				"Address::8000 " + | ||||
| 				"TLS:goo,gii " + | ||||
| 				"TLS " + | ||||
| 				"CA:car " + | ||||
| 				"CA.Optional:true " + | ||||
| 				"Redirect.EntryPoint:https " + | ||||
| 				"Redirect.Regex:http://localhost/(.*) " + | ||||
| 				"Redirect.Replacement:http://mydomain/$1 " + | ||||
| 				"Redirect.Permanent:true " + | ||||
| 				"Compress:true " + | ||||
| 				"ProxyProtocol.TrustedIPs:192.168.0.1 " + | ||||
| 				"ForwardedHeaders.TrustedIPs:10.0.0.3/24,20.0.0.3/24 " + | ||||
| 				"Auth.Basic.Users:test:$apr1$H6uskkkW$IgXLP6ewTrSuBkTrqE8wj/,test2:$apr1$d9hr9HBB$4HxwgUir3HP4EsggP/QNo0 " + | ||||
| 				"Auth.Digest.Users:test:traefik:a2688e031edb4be6a3797f3882655c05,test2:traefik:518845800f9e2bfb1f1f740ec24f074e " + | ||||
| 				"Auth.HeaderField:X-WebAuth-User " + | ||||
| 				"Auth.Forward.Address:https://authserver.com/auth " + | ||||
| 				"Auth.Forward.TrustForwardHeader:true " + | ||||
| 				"Auth.Forward.TLS.CA:path/to/local.crt " + | ||||
| 				"Auth.Forward.TLS.CAOptional:true " + | ||||
| 				"Auth.Forward.TLS.Cert:path/to/foo.cert " + | ||||
| 				"Auth.Forward.TLS.Key:path/to/foo.key " + | ||||
| 				"Auth.Forward.TLS.InsecureSkipVerify:true " + | ||||
| 				"WhiteListSourceRange:10.42.0.0/16,152.89.1.33/32,afed:be44::/16 " + | ||||
| 				"whiteList.sourceRange:10.42.0.0/16,152.89.1.33/32,afed:be44::/16 " + | ||||
| 				"whiteList.useXForwardedFor:true ", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				Address: ":8000", | ||||
| 				TLS: &tls.TLS{ | ||||
| 					Certificates: tls.Certificates{ | ||||
| 						{ | ||||
| 							CertFile: tls.FileOrContent("goo"), | ||||
| 							KeyFile:  tls.FileOrContent("gii"), | ||||
| 						}, | ||||
| 					}, | ||||
| 					ClientCA: tls.ClientCA{ | ||||
| 						Files:    []string{"car"}, | ||||
| 						Optional: true, | ||||
| 					}, | ||||
| 				}, | ||||
| 				Redirect: &types.Redirect{ | ||||
| 					EntryPoint:  "https", | ||||
| 					Regex:       "http://localhost/(.*)", | ||||
| 					Replacement: "http://mydomain/$1", | ||||
| 					Permanent:   true, | ||||
| 				}, | ||||
| 				Auth: &types.Auth{ | ||||
| 					Basic: &types.Basic{ | ||||
| 						Users: types.Users{ | ||||
| 							"test:$apr1$H6uskkkW$IgXLP6ewTrSuBkTrqE8wj/", | ||||
| 							"test2:$apr1$d9hr9HBB$4HxwgUir3HP4EsggP/QNo0", | ||||
| 						}, | ||||
| 					}, | ||||
| 					Digest: &types.Digest{ | ||||
| 						Users: types.Users{ | ||||
| 							"test:traefik:a2688e031edb4be6a3797f3882655c05", | ||||
| 							"test2:traefik:518845800f9e2bfb1f1f740ec24f074e", | ||||
| 						}, | ||||
| 					}, | ||||
| 					Forward: &types.Forward{ | ||||
| 						Address: "https://authserver.com/auth", | ||||
| 						TLS: &types.ClientTLS{ | ||||
| 							CA:                 "path/to/local.crt", | ||||
| 							CAOptional:         true, | ||||
| 							Cert:               "path/to/foo.cert", | ||||
| 							Key:                "path/to/foo.key", | ||||
| 							InsecureSkipVerify: true, | ||||
| 						}, | ||||
| 						TrustForwardHeader: true, | ||||
| 					}, | ||||
| 					HeaderField: "X-WebAuth-User", | ||||
| 				}, | ||||
| 				WhitelistSourceRange: []string{ | ||||
| 					"10.42.0.0/16", | ||||
| 					"152.89.1.33/32", | ||||
| 					"afed:be44::/16", | ||||
| 				}, | ||||
| 				WhiteList: &types.WhiteList{ | ||||
| 					SourceRange: []string{ | ||||
| 						"10.42.0.0/16", | ||||
| 						"152.89.1.33/32", | ||||
| 						"afed:be44::/16", | ||||
| 					}, | ||||
| 					UseXForwardedFor: true, | ||||
| 				}, | ||||
| 				Compress: true, | ||||
| 				ProxyProtocol: &ProxyProtocol{ | ||||
| 					Insecure:   false, | ||||
| 					TrustedIPs: []string{"192.168.0.1"}, | ||||
| 				}, | ||||
| 				ForwardedHeaders: &ForwardedHeaders{ | ||||
| 					Insecure: false, | ||||
| 					TrustedIPs: []string{ | ||||
| 						"10.0.0.3/24", | ||||
| 						"20.0.0.3/24", | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name: "all parameters lowercase", | ||||
| 			expression: "Name:foo " + | ||||
| 				"address::8000 " + | ||||
| 				"tls:goo,gii " + | ||||
| 				"tls " + | ||||
| 				"ca:car " + | ||||
| 				"ca.Optional:true " + | ||||
| 				"redirect.entryPoint:https " + | ||||
| 				"redirect.regex:http://localhost/(.*) " + | ||||
| 				"redirect.replacement:http://mydomain/$1 " + | ||||
| 				"redirect.permanent:true " + | ||||
| 				"compress:true " + | ||||
| 				"whiteListSourceRange:10.42.0.0/16,152.89.1.33/32,afed:be44::/16 " + | ||||
| 				"proxyProtocol.TrustedIPs:192.168.0.1 " + | ||||
| 				"forwardedHeaders.TrustedIPs:10.0.0.3/24,20.0.0.3/24 " + | ||||
| 				"auth.basic.users:test:$apr1$H6uskkkW$IgXLP6ewTrSuBkTrqE8wj/,test2:$apr1$d9hr9HBB$4HxwgUir3HP4EsggP/QNo0 " + | ||||
| 				"auth.digest.users:test:traefik:a2688e031edb4be6a3797f3882655c05,test2:traefik:518845800f9e2bfb1f1f740ec24f074e " + | ||||
| 				"auth.headerField:X-WebAuth-User " + | ||||
| 				"auth.forward.address:https://authserver.com/auth " + | ||||
| 				"auth.forward.trustForwardHeader:true " + | ||||
| 				"auth.forward.tls.ca:path/to/local.crt " + | ||||
| 				"auth.forward.tls.caOptional:true " + | ||||
| 				"auth.forward.tls.cert:path/to/foo.cert " + | ||||
| 				"auth.forward.tls.key:path/to/foo.key " + | ||||
| 				"auth.forward.tls.insecureSkipVerify:true ", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				Address: ":8000", | ||||
| 				TLS: &tls.TLS{ | ||||
| 					Certificates: tls.Certificates{ | ||||
| 						{ | ||||
| 							CertFile: tls.FileOrContent("goo"), | ||||
| 							KeyFile:  tls.FileOrContent("gii"), | ||||
| 						}, | ||||
| 					}, | ||||
| 					ClientCA: tls.ClientCA{ | ||||
| 						Files:    []string{"car"}, | ||||
| 						Optional: true, | ||||
| 					}, | ||||
| 				}, | ||||
| 				Redirect: &types.Redirect{ | ||||
| 					EntryPoint:  "https", | ||||
| 					Regex:       "http://localhost/(.*)", | ||||
| 					Replacement: "http://mydomain/$1", | ||||
| 					Permanent:   true, | ||||
| 				}, | ||||
| 				Auth: &types.Auth{ | ||||
| 					Basic: &types.Basic{ | ||||
| 						Users: types.Users{ | ||||
| 							"test:$apr1$H6uskkkW$IgXLP6ewTrSuBkTrqE8wj/", | ||||
| 							"test2:$apr1$d9hr9HBB$4HxwgUir3HP4EsggP/QNo0", | ||||
| 						}, | ||||
| 					}, | ||||
| 					Digest: &types.Digest{ | ||||
| 						Users: types.Users{ | ||||
| 							"test:traefik:a2688e031edb4be6a3797f3882655c05", | ||||
| 							"test2:traefik:518845800f9e2bfb1f1f740ec24f074e", | ||||
| 						}, | ||||
| 					}, | ||||
| 					Forward: &types.Forward{ | ||||
| 						Address: "https://authserver.com/auth", | ||||
| 						TLS: &types.ClientTLS{ | ||||
| 							CA:                 "path/to/local.crt", | ||||
| 							CAOptional:         true, | ||||
| 							Cert:               "path/to/foo.cert", | ||||
| 							Key:                "path/to/foo.key", | ||||
| 							InsecureSkipVerify: true, | ||||
| 						}, | ||||
| 						TrustForwardHeader: true, | ||||
| 					}, | ||||
| 					HeaderField: "X-WebAuth-User", | ||||
| 				}, | ||||
| 				WhitelistSourceRange: []string{ | ||||
| 					"10.42.0.0/16", | ||||
| 					"152.89.1.33/32", | ||||
| 					"afed:be44::/16", | ||||
| 				}, | ||||
| 				Compress: true, | ||||
| 				ProxyProtocol: &ProxyProtocol{ | ||||
| 					Insecure:   false, | ||||
| 					TrustedIPs: []string{"192.168.0.1"}, | ||||
| 				}, | ||||
| 				ForwardedHeaders: &ForwardedHeaders{ | ||||
| 					Insecure: false, | ||||
| 					TrustedIPs: []string{ | ||||
| 						"10.0.0.3/24", | ||||
| 						"20.0.0.3/24", | ||||
| 					}, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:                   "default", | ||||
| 			expression:             "Name:foo", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				ForwardedHeaders: &ForwardedHeaders{Insecure: true}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:                   "ForwardedHeaders insecure true", | ||||
| 			expression:             "Name:foo ForwardedHeaders.Insecure:true", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				ForwardedHeaders: &ForwardedHeaders{Insecure: true}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:                   "ForwardedHeaders insecure false", | ||||
| 			expression:             "Name:foo ForwardedHeaders.Insecure:false", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				ForwardedHeaders: &ForwardedHeaders{Insecure: false}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:                   "ForwardedHeaders TrustedIPs", | ||||
| 			expression:             "Name:foo ForwardedHeaders.TrustedIPs:10.0.0.3/24,20.0.0.3/24", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				ForwardedHeaders: &ForwardedHeaders{ | ||||
| 					TrustedIPs: []string{"10.0.0.3/24", "20.0.0.3/24"}, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:                   "ProxyProtocol insecure true", | ||||
| 			expression:             "Name:foo ProxyProtocol.Insecure:true", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				ForwardedHeaders: &ForwardedHeaders{Insecure: true}, | ||||
| 				ProxyProtocol:    &ProxyProtocol{Insecure: true}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:                   "ProxyProtocol insecure false", | ||||
| 			expression:             "Name:foo ProxyProtocol.Insecure:false", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				ForwardedHeaders: &ForwardedHeaders{Insecure: true}, | ||||
| 				ProxyProtocol:    &ProxyProtocol{}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:                   "ProxyProtocol TrustedIPs", | ||||
| 			expression:             "Name:foo ProxyProtocol.TrustedIPs:10.0.0.3/24,20.0.0.3/24", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				ForwardedHeaders: &ForwardedHeaders{Insecure: true}, | ||||
| 				ProxyProtocol: &ProxyProtocol{ | ||||
| 					TrustedIPs: []string{"10.0.0.3/24", "20.0.0.3/24"}, | ||||
| 				}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:                   "compress on", | ||||
| 			expression:             "Name:foo Compress:on", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				Compress:         true, | ||||
| 				ForwardedHeaders: &ForwardedHeaders{Insecure: true}, | ||||
| 			}, | ||||
| 		}, | ||||
| 		{ | ||||
| 			name:                   "compress true", | ||||
| 			expression:             "Name:foo Compress:true", | ||||
| 			expectedEntryPointName: "foo", | ||||
| 			expectedEntryPoint: &EntryPoint{ | ||||
| 				Compress:         true, | ||||
| 				ForwardedHeaders: &ForwardedHeaders{Insecure: true}, | ||||
| 			}, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	for _, test := range testCases { | ||||
| 		test := test | ||||
| 		t.Run(test.name, func(t *testing.T) { | ||||
| 			t.Parallel() | ||||
|  | ||||
| 			eps := EntryPoints{} | ||||
| 			err := eps.Set(test.expression) | ||||
| 			require.NoError(t, err) | ||||
|  | ||||
| 			ep := eps[test.expectedEntryPointName] | ||||
| 			assert.EqualValues(t, test.expectedEntryPoint, ep) | ||||
| 		}) | ||||
| 	} | ||||
| } | ||||
| @@ -1,97 +0,0 @@ | ||||
| package configuration | ||||
|  | ||||
| import ( | ||||
| 	"encoding/json" | ||||
| 	"reflect" | ||||
|  | ||||
| 	"github.com/containous/traefik/acme" | ||||
| 	"github.com/containous/traefik/log" | ||||
| 	"github.com/containous/traefik/provider" | ||||
| 	acmeprovider "github.com/containous/traefik/provider/acme" | ||||
| 	"github.com/containous/traefik/safe" | ||||
| 	"github.com/containous/traefik/types" | ||||
| ) | ||||
|  | ||||
| type providerAggregator struct { | ||||
| 	providers []provider.Provider | ||||
| } | ||||
|  | ||||
| // NewProviderAggregator return an aggregate of all the providers configured in GlobalConfiguration | ||||
| func NewProviderAggregator(gc *GlobalConfiguration) provider.Provider { | ||||
| 	provider := providerAggregator{} | ||||
| 	if gc.Docker != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Docker) | ||||
| 	} | ||||
| 	if gc.Marathon != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Marathon) | ||||
| 	} | ||||
| 	if gc.File != nil { | ||||
| 		provider.providers = append(provider.providers, gc.File) | ||||
| 	} | ||||
| 	if gc.Rest != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Rest) | ||||
| 	} | ||||
| 	if gc.Consul != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Consul) | ||||
| 	} | ||||
| 	if gc.ConsulCatalog != nil { | ||||
| 		provider.providers = append(provider.providers, gc.ConsulCatalog) | ||||
| 	} | ||||
| 	if gc.Etcd != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Etcd) | ||||
| 	} | ||||
| 	if gc.Zookeeper != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Zookeeper) | ||||
| 	} | ||||
| 	if gc.Boltdb != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Boltdb) | ||||
| 	} | ||||
| 	if gc.Kubernetes != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Kubernetes) | ||||
| 	} | ||||
| 	if gc.Mesos != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Mesos) | ||||
| 	} | ||||
| 	if gc.Eureka != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Eureka) | ||||
| 	} | ||||
| 	if gc.ECS != nil { | ||||
| 		provider.providers = append(provider.providers, gc.ECS) | ||||
| 	} | ||||
| 	if gc.Rancher != nil { | ||||
| 		provider.providers = append(provider.providers, gc.Rancher) | ||||
| 	} | ||||
| 	if gc.DynamoDB != nil { | ||||
| 		provider.providers = append(provider.providers, gc.DynamoDB) | ||||
| 	} | ||||
| 	if gc.ServiceFabric != nil { | ||||
| 		provider.providers = append(provider.providers, gc.ServiceFabric) | ||||
| 	} | ||||
| 	if acmeprovider.IsEnabled() { | ||||
| 		provider.providers = append(provider.providers, acmeprovider.Get()) | ||||
| 		acme.ConvertToNewFormat(acmeprovider.Get().Storage) | ||||
| 	} | ||||
| 	if len(provider.providers) == 1 { | ||||
| 		return provider.providers[0] | ||||
| 	} | ||||
| 	return provider | ||||
| } | ||||
|  | ||||
| func (p providerAggregator) Provide(configurationChan chan<- types.ConfigMessage, pool *safe.Pool, constraints types.Constraints) error { | ||||
| 	for _, p := range p.providers { | ||||
| 		providerType := reflect.TypeOf(p) | ||||
| 		jsonConf, err := json.Marshal(p) | ||||
| 		if err != nil { | ||||
| 			log.Debugf("Unable to marshal provider conf %v with error: %v", providerType, err) | ||||
| 		} | ||||
| 		log.Infof("Starting provider %v %s", providerType, jsonConf) | ||||
| 		currentProvider := p | ||||
| 		safe.Go(func() { | ||||
| 			err := currentProvider.Provide(configurationChan, pool, constraints) | ||||
| 			if err != nil { | ||||
| 				log.Errorf("Error starting provider %v: %s", providerType, err) | ||||
| 			} | ||||
| 		}) | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
							
								
								
									
										1577
									
								
								contrib/grafana/traefik-kubernetes.json
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										1577
									
								
								contrib/grafana/traefik-kubernetes.json
									
									
									
									
									
										Normal file
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										1507
									
								
								contrib/grafana/traefik.json
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										1507
									
								
								contrib/grafana/traefik.json
									
									
									
									
									
										Normal file
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							| @@ -1,170 +0,0 @@ | ||||
| #!/usr/bin/env bash | ||||
| # Copyright (c) 2017 Brian 'redbeard' Harrington <redbeard@dead-city.org> | ||||
| # | ||||
| # dumpcerts.sh - A simple utility to explode a Traefik acme.json file into a | ||||
| #                directory of certificates and a private key | ||||
| # | ||||
| # Usage - dumpcerts.sh /etc/traefik/acme.json /etc/ssl/ | ||||
| # | ||||
| # Dependencies - | ||||
| #   util-linux | ||||
| #   openssl | ||||
| #   jq | ||||
| # The MIT License (MIT) | ||||
| # | ||||
| # Permission is hereby granted, free of charge, to any person obtaining a copy | ||||
| # of this software and associated documentation files (the "Software"), to deal | ||||
| # in the Software without restriction, including without limitation the rights | ||||
| # to use, copy, modify, merge, publish, distribute, sublicense, and/or sell | ||||
| # copies of the Software, and to permit persons to whom the Software is | ||||
| # furnished to do so, subject to the following conditions: | ||||
| # | ||||
| # The above copyright notice and this permission notice shall be included in | ||||
| # all copies or substantial portions of the Software. | ||||
| # | ||||
| # THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR | ||||
| # IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, | ||||
| # FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE | ||||
| # AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER | ||||
| # LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, | ||||
| # OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN | ||||
| # THE SOFTWARE. | ||||
|  | ||||
| # Exit codes: | ||||
| # 1 - A component is missing or could not be read | ||||
| # 2 - There was a problem reading acme.json | ||||
| # 4 - The destination certificate directory does not exist | ||||
| # 8 - Missing private key | ||||
|  | ||||
| set -o errexit | ||||
| set -o pipefail | ||||
| set -o nounset | ||||
|  | ||||
| USAGE="$(basename "$0") <path to acme> <destination cert directory>" | ||||
|  | ||||
| # Platform variations | ||||
| case "$(uname)" in | ||||
| 	'Linux') | ||||
| 		# On Linux, -d should always work. --decode does not work with Alpine's busybox-binary | ||||
| 		CMD_DECODE_BASE64="base64 -d" | ||||
| 		;; | ||||
| 	*) | ||||
| 		# Max OS-X supports --decode and -D, but --decode may be supported by other platforms as well. | ||||
| 		CMD_DECODE_BASE64="base64 --decode" | ||||
| 		;; | ||||
| esac | ||||
|  | ||||
| # Allow us to exit on a missing jq binary | ||||
| exit_jq() { | ||||
| 	echo " | ||||
| You must have the binary 'jq' to use this. | ||||
| jq is available at: https://stedolan.github.io/jq/download/ | ||||
|  | ||||
| ${USAGE}" >&2 | ||||
| 	exit 1 | ||||
| } | ||||
|  | ||||
| bad_acme() { | ||||
| 	echo " | ||||
| There was a problem parsing your acme.json file. $1 | ||||
|  | ||||
| ${USAGE}" >&2 | ||||
| 	exit 2 | ||||
| } | ||||
|  | ||||
| if [ $# -ne 2 ]; then | ||||
| 	echo " | ||||
| Insufficient number of parameters. | ||||
|  | ||||
| ${USAGE}" >&2 | ||||
| 	exit 1 | ||||
| fi | ||||
|  | ||||
| readonly acmefile="${1}" | ||||
| readonly certdir="${2%/}" | ||||
|  | ||||
| if [ ! -r "${acmefile}" ]; then | ||||
| 	echo " | ||||
| There was a problem reading from '${acmefile}' | ||||
| We need to read this file to explode the JSON bundle... exiting. | ||||
|  | ||||
| ${USAGE}" >&2 | ||||
| 	exit 2 | ||||
| fi | ||||
|  | ||||
|  | ||||
| if [ ! -d "${certdir}" ]; then | ||||
| 	echo " | ||||
| Path ${certdir} does not seem to be a directory | ||||
| We need a directory in which to explode the JSON bundle... exiting. | ||||
|  | ||||
| ${USAGE}" >&2 | ||||
| 	exit 4 | ||||
| fi | ||||
|  | ||||
| jq=$(command -v jq) || exit_jq | ||||
|  | ||||
| priv=$(${jq} -e -r '.Account.PrivateKey' "${acmefile}") || bad_acme | ||||
|  | ||||
| if [ ! -n "${priv}" ]; then | ||||
| 	echo " | ||||
| There didn't seem to be a private key in ${acmefile}. | ||||
| Please ensure that there is a key in this file and try again." >&2 | ||||
| 	exit 8 | ||||
| fi | ||||
|  | ||||
| # If they do not exist, create the needed subdirectories for our assets | ||||
| # and place each in a variable for later use, normalizing the path | ||||
| mkdir -p "${certdir}"/{certs,private} | ||||
|  | ||||
| pdir="${certdir}/private/" | ||||
| cdir="${certdir}/certs/" | ||||
|  | ||||
| # Save the existing umask, change the default mode to 600, then | ||||
| # after writing the private key switch it back to the default | ||||
| oldumask=$(umask) | ||||
| umask 177 | ||||
| trap 'umask ${oldumask}' EXIT | ||||
|  | ||||
| # traefik stores the private key in stripped base64 format but the certificates | ||||
| # bundled as a base64 object without stripping headers.  This normalizes the | ||||
| # headers and formatting. | ||||
| # | ||||
| # In testing this out it was a balance between the following mechanisms: | ||||
| # gawk: | ||||
| #  echo ${priv} | awk 'BEGIN {print "-----BEGIN RSA PRIVATE KEY-----"} | ||||
| #     {gsub(/.{64}/,"&\n")}1 | ||||
| #     END {print "-----END RSA PRIVATE KEY-----"}' > "${pdir}/letsencrypt.key" | ||||
| # | ||||
| # openssl: | ||||
| # echo -e "-----BEGIN RSA PRIVATE KEY-----\n${priv}\n-----END RSA PRIVATE KEY-----" \ | ||||
| #   | openssl rsa -inform pem -out "${pdir}/letsencrypt.key" | ||||
| # | ||||
| # and sed: | ||||
| # echo "-----BEGIN RSA PRIVATE KEY-----" > "${pdir}/letsencrypt.key" | ||||
| # echo ${priv} | sed -E 's/(.{64})/\1\n/g' >> "${pdir}/letsencrypt.key" | ||||
| # sed -i '$ d' "${pdir}/letsencrypt.key" | ||||
| # echo "-----END RSA PRIVATE KEY-----" >> "${pdir}/letsencrypt.key" | ||||
| # openssl rsa -noout -in "${pdir}/letsencrypt.key" -check  # To check if the key is valid | ||||
|  | ||||
| # In the end, openssl was chosen because most users will need this script | ||||
| # *because* of openssl combined with the fact that it will refuse to write the | ||||
| # key if it does not parse out correctly. The other mechanisms were left as | ||||
| # comments so that the user can choose the mechanism most appropriate to them. | ||||
| echo -e "-----BEGIN RSA PRIVATE KEY-----\n${priv}\n-----END RSA PRIVATE KEY-----" \ | ||||
|    | openssl rsa -inform pem -out "${pdir}/letsencrypt.key" | ||||
|  | ||||
| # Process the certificates for each of the domains in acme.json | ||||
| for domain in $(jq -r '.Certificates[].Domain.Main' ${acmefile}); do | ||||
| 	# Traefik stores a cert bundle for each domain.  Within this cert | ||||
| 	# bundle there is both proper the certificate and the Let's Encrypt CA | ||||
| 	echo "Extracting cert bundle for ${domain}" | ||||
| 	cert=$(jq -e -r --arg domain "$domain" '.Certificates[] | | ||||
|          	select (.Domain.Main == $domain )| .Certificate' ${acmefile}) || bad_acme | ||||
| 	echo "${cert}" | ${CMD_DECODE_BASE64} > "${cdir}/${domain}.crt" | ||||
|  | ||||
| 	echo "Extracting private key for ${domain}" | ||||
| 	key=$(jq -e -r --arg domain "$domain" '.Certificates[] | | ||||
| 		select (.Domain.Main == $domain )| .Key' ${acmefile}) || bad_acme | ||||
| 	echo "${key}" | ${CMD_DECODE_BASE64} > "${pdir}/${domain}.key" | ||||
| done | ||||
| @@ -1,11 +1,41 @@ | ||||
| [Unit] | ||||
| Description=Traefik | ||||
| Documentation=https://doc.traefik.io/traefik/ | ||||
| #After=network-online.target | ||||
| #AssertFileIsExecutable=/usr/bin/traefik | ||||
| #AssertPathExists=/etc/traefik/traefik.toml | ||||
|  | ||||
| [Service] | ||||
| # Run traefik as its own user (create new user with: useradd -r -s /bin/false -U -M traefik) | ||||
| #User=traefik | ||||
| #AmbientCapabilities=CAP_NET_BIND_SERVICE | ||||
|  | ||||
| # configure service behavior | ||||
| Type=notify | ||||
| ExecStart=/usr/bin/traefik --configFile=/etc/traefik.toml | ||||
| #ExecStart=/usr/bin/traefik --configFile=/etc/traefik/traefik.toml | ||||
| Restart=always | ||||
| WatchdogSec=1s | ||||
|  | ||||
| # lock down system access | ||||
| # prohibit any operating system and configuration modification | ||||
| #ProtectSystem=strict | ||||
| # create separate, new (and empty) /tmp and /var/tmp filesystems | ||||
| #PrivateTmp=true | ||||
| # make /home directories inaccessible | ||||
| #ProtectHome=true | ||||
| # turns off access to physical devices (/dev/...) | ||||
| #PrivateDevices=true | ||||
| # make kernel settings (procfs and sysfs) read-only | ||||
| #ProtectKernelTunables=true | ||||
| # make cgroups /sys/fs/cgroup read-only | ||||
| #ProtectControlGroups=true | ||||
|  | ||||
| # allow writing of acme.json | ||||
| #ReadWritePaths=/etc/traefik/acme.json | ||||
| # depending on log and entrypoint configuration, you may need to allow writing to other paths, too | ||||
|  | ||||
| # limit number of processes in this unit | ||||
| #LimitNPROC=1 | ||||
|  | ||||
| [Install] | ||||
| WantedBy=multi-user.target | ||||
|   | ||||
| @@ -1,11 +0,0 @@ | ||||
| FROM alpine | ||||
|  | ||||
| ENV PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/root/.local/bin | ||||
|  | ||||
| COPY requirements.txt /mkdocs/ | ||||
| WORKDIR /mkdocs | ||||
|  | ||||
| RUN apk --update upgrade \ | ||||
| && apk --no-cache --no-progress add py-pip \ | ||||
| && rm -rf /var/cache/apk/* \ | ||||
| && pip install --user -r requirements.txt | ||||
							
								
								
									
										1
									
								
								docs/.dockerignore
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										1
									
								
								docs/.dockerignore
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1 @@ | ||||
| site/ | ||||
							
								
								
									
										13
									
								
								docs/.markdownlint.json
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										13
									
								
								docs/.markdownlint.json
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,13 @@ | ||||
| { | ||||
|     "no-hard-tabs": false, | ||||
|     "MD007": { "indent": 4 }, | ||||
|     "MD009": false, | ||||
|     "MD013": false, | ||||
|     "MD024": false, | ||||
|     "MD025": false, | ||||
|     "MD026": false, | ||||
|     "MD033": false, | ||||
|     "MD034": false, | ||||
|     "MD036": false, | ||||
|     "MD046": false | ||||
| } | ||||
| @@ -1 +0,0 @@ | ||||
| docs.traefik.io | ||||
							
								
								
									
										65
									
								
								docs/Makefile
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										65
									
								
								docs/Makefile
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,65 @@ | ||||
| ####### | ||||
| # This Makefile contains all targets related to the documentation | ||||
| ####### | ||||
|  | ||||
| DOCS_VERIFY_SKIP ?= false | ||||
| DOCS_LINT_SKIP ?= false | ||||
|  | ||||
| TRAEFIK_DOCS_BUILD_IMAGE ?= traefik-docs | ||||
| TRAEFIK_DOCS_CHECK_IMAGE ?= $(TRAEFIK_DOCS_BUILD_IMAGE)-check | ||||
|  | ||||
| SITE_DIR := $(CURDIR)/site | ||||
|  | ||||
| DOCKER_RUN_DOC_PORT := 8000 | ||||
| DOCKER_RUN_DOC_MOUNTS := -v $(CURDIR):/mkdocs | ||||
| DOCKER_RUN_DOC_OPTS := --rm $(DOCKER_RUN_DOC_MOUNTS) -p $(DOCKER_RUN_DOC_PORT):8000 | ||||
|  | ||||
| # Default: generates the documentation into $(SITE_DIR) | ||||
| .PHONY: docs | ||||
| docs: docs-clean docs-image docs-lint docs-build docs-verify | ||||
|  | ||||
| # Writer Mode: build and serve docs on http://localhost:8000 with livereload | ||||
| .PHONY: docs-serve | ||||
| docs-serve: docs-image | ||||
| 	docker run  $(DOCKER_RUN_DOC_OPTS) $(TRAEFIK_DOCS_BUILD_IMAGE) mkdocs serve | ||||
|  | ||||
| ## Pull image for doc building | ||||
| .PHONY: docs-pull-images | ||||
| docs-pull-images: | ||||
| 	grep --no-filename -E '^FROM' ./*.Dockerfile \ | ||||
| 		| awk '{print $$2}' \ | ||||
| 		| sort \ | ||||
| 		| uniq \ | ||||
| 		| xargs -P 6 -n 1 docker pull | ||||
|  | ||||
| # Utilities Targets for each step | ||||
| .PHONY: docs-image | ||||
| docs-image: | ||||
| 	docker build -t $(TRAEFIK_DOCS_BUILD_IMAGE) -f docs.Dockerfile ./ | ||||
|  | ||||
| .PHONY: docs-build | ||||
| docs-build: docs-image | ||||
| 	docker run $(DOCKER_RUN_DOC_OPTS) $(TRAEFIK_DOCS_BUILD_IMAGE) sh -c "mkdocs build \ | ||||
| 		&& chown -R $(shell id -u):$(shell id -g) ./site" | ||||
|  | ||||
| .PHONY: docs-verify | ||||
| docs-verify: docs-build | ||||
| ifneq ("$(DOCS_VERIFY_SKIP)", "true") | ||||
| 	docker build -t $(TRAEFIK_DOCS_CHECK_IMAGE) -f check.Dockerfile ./ | ||||
| 	docker run --rm -v $(CURDIR):/app $(TRAEFIK_DOCS_CHECK_IMAGE) /verify.sh | ||||
| else | ||||
| 	echo "DOCS_VERIFY_SKIP is true: no verification done." | ||||
| endif | ||||
|  | ||||
| .PHONY: docs-lint | ||||
| docs-lint: | ||||
| ifneq ("$(DOCS_LINT_SKIP)", "true") | ||||
| 	docker build -t $(TRAEFIK_DOCS_CHECK_IMAGE) -f check.Dockerfile ./ | ||||
| 	docker run --rm -v $(CURDIR):/app $(TRAEFIK_DOCS_CHECK_IMAGE) /lint.sh | ||||
| else | ||||
| 	echo "DOCS_LINT_SKIP is true: no linting done." | ||||
| endif | ||||
|  | ||||
| .PHONY: docs-clean | ||||
| docs-clean: | ||||
| 	rm -rf $(SITE_DIR) | ||||
							
								
								
									
										719
									
								
								docs/basics.md
									
									
									
									
									
								
							
							
						
						
									
										719
									
								
								docs/basics.md
									
									
									
									
									
								
							| @@ -1,719 +0,0 @@ | ||||
| # Basics | ||||
|  | ||||
| ## Concepts | ||||
|  | ||||
| Let's take our example from the [overview](/#overview) again: | ||||
|  | ||||
|  | ||||
| > Imagine that you have deployed a bunch of microservices on your infrastructure. You probably used a service registry (like etcd or consul) and/or an orchestrator (swarm, Mesos/Marathon) to manage all these services. | ||||
| > If you want your users to access some of your microservices from the Internet, you will have to use a reverse proxy and configure it using virtual hosts or prefix paths: | ||||
|  | ||||
| > - domain `api.domain.com` will point the microservice `api` in your private network | ||||
| > - path `domain.com/web` will point the microservice `web` in your private network | ||||
| > - domain `backoffice.domain.com` will point the microservices `backoffice` in your private network, load-balancing between your multiple instances | ||||
|  | ||||
| >  | ||||
|  | ||||
| Let's zoom on Træfik and have an overview of its internal architecture: | ||||
|  | ||||
|  | ||||
|  | ||||
|  | ||||
| - Incoming requests end on [entrypoints](#entrypoints), as the name suggests, they are the network entry points into Træfik (listening port, SSL, traffic redirection...). | ||||
| - Traffic is then forwarded to a matching [frontend](#frontends). A frontend defines routes from [entrypoints](#entrypoints) to [backends](#backends). | ||||
| Routes are created using requests fields (`Host`, `Path`, `Headers`...) and can match or not a request. | ||||
| - The [frontend](#frontends) will then send the request to a [backend](#backends). A backend can be composed by one or more [servers](#servers), and by a load-balancing strategy. | ||||
| - Finally, the [server](#servers) will forward the request to the corresponding microservice in the private network. | ||||
|  | ||||
| ### Entrypoints | ||||
|  | ||||
| Entrypoints are the network entry points into Træfik. | ||||
| They can be defined using: | ||||
|  | ||||
| - a port (80, 443...) | ||||
| - SSL (Certificates, Keys, authentication with a client certificate signed by a trusted CA...) | ||||
| - redirection to another entrypoint (redirect `HTTP` to `HTTPS`) | ||||
|  | ||||
| Here is an example of entrypoints definition: | ||||
|  | ||||
| ```toml | ||||
| [entryPoints] | ||||
|   [entryPoints.http] | ||||
|   address = ":80" | ||||
|     [entryPoints.http.redirect] | ||||
|     entryPoint = "https" | ||||
|   [entryPoints.https] | ||||
|   address = ":443" | ||||
|     [entryPoints.https.tls] | ||||
|       [[entryPoints.https.tls.certificates]] | ||||
|       certFile = "tests/traefik.crt" | ||||
|       keyFile = "tests/traefik.key" | ||||
| ``` | ||||
|  | ||||
| - Two entrypoints are defined `http` and `https`. | ||||
| - `http` listens on port `80` and `https` on port `443`. | ||||
| - We enable SSL on `https` by giving a certificate and a key. | ||||
| - We also redirect all the traffic from entrypoint `http` to `https`. | ||||
|  | ||||
| And here is another example with client certificate authentication: | ||||
|  | ||||
| ```toml | ||||
| [entryPoints] | ||||
|   [entryPoints.https] | ||||
|   address = ":443" | ||||
|   [entryPoints.https.tls] | ||||
|     [entryPoints.https.tls.ClientCA] | ||||
|     files = ["tests/clientca1.crt", "tests/clientca2.crt"] | ||||
|     optional = false | ||||
|     [[entryPoints.https.tls.certificates]] | ||||
|     certFile = "tests/traefik.crt" | ||||
|     keyFile = "tests/traefik.key" | ||||
| ``` | ||||
|  | ||||
| - We enable SSL on `https` by giving a certificate and a key. | ||||
| - One or several files containing Certificate Authorities in PEM format are added. | ||||
| - It is possible to have multiple CA:s in the same file or keep them in separate files. | ||||
|  | ||||
| ### Frontends | ||||
|  | ||||
| A frontend consists of a set of rules that determine how incoming requests are forwarded from an entrypoint to a backend. | ||||
|  | ||||
| Rules may be classified in one of two groups: Modifiers and matchers. | ||||
|  | ||||
| #### Modifiers | ||||
|  | ||||
| Modifier rules only modify the request. They do not have any impact on routing decisions being made. | ||||
|  | ||||
| Following is the list of existing modifier rules: | ||||
|  | ||||
| - `AddPrefix: /products`: Add path prefix to the existing request path prior to forwarding the request to the backend. | ||||
| - `ReplacePath: /serverless-path`: Replaces the path and adds the old path to the `X-Replaced-Path` header. Useful for mapping to AWS Lambda or Google Cloud Functions. | ||||
| - `ReplacePathRegex: ^/api/v2/(.*) /api/$1`: Replaces the path with a regular expression and adds the old path to the `X-Replaced-Path` header. Separate the regular expression and the replacement by a space. | ||||
|  | ||||
| #### Matchers | ||||
|  | ||||
| Matcher rules determine if a particular request should be forwarded to a backend. | ||||
|  | ||||
| Separate multiple rule values by `,` (comma) in order to enable ANY semantics (i.e., forward a request if any rule matches). | ||||
| Does not work for `Headers` and `HeadersRegexp`. | ||||
|  | ||||
| Separate multiple rule values by `;` (semicolon) in order to enable ALL semantics (i.e., forward a request if all rules match). | ||||
|  | ||||
| Following is the list of existing matcher rules along with examples: | ||||
|  | ||||
| | Matcher                                                    | Description                                                                                                                                                                                                                                                                             | | ||||
| |------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | ||||
| | `Headers: Content-Type, application/json`                  | Match HTTP header. It accepts a comma-separated key/value pair where both key and value must be literals.                                                                                                                                                                               | | ||||
| | `HeadersRegexp: Content-Type, application/(text/json)`     | Match HTTP header. It accepts a comma-separated key/value pair where the key must be a literal and the value may be a literal or a regular expression.                                                                                                                                  | | ||||
| | `Host: traefik.io, www.traefik.io`                         | Match request host. It accepts a sequence of literal hosts.                                                                                                                                                                                                                             | | ||||
| | `HostRegexp: traefik.io, {subdomain:[a-z]+}.traefik.io`    | Match request host. It accepts a sequence of literal and regular expression hosts.                                                                                                                                                                                                      | | ||||
| | `Method: GET, POST, PUT`                                   | Match request HTTP method. It accepts a sequence of HTTP methods.                                                                                                                                                                                                                       | | ||||
| | `Path: /products/, /articles/{category}/{id:[0-9]+}`       | Match exact request path. It accepts a sequence of literal and regular expression paths.                                                                                                                                                                                                | | ||||
| | `PathStrip: /products/`                                    | Match exact path and strip off the path prior to forwarding the request to the backend. It accepts a sequence of literal paths.                                                                                                                                                         | | ||||
| | `PathStripRegex: /articles/{category}/{id:[0-9]+}`         | Match exact path and strip off the path prior to forwarding the request to the backend. It accepts a sequence of literal and regular expression paths.                                                                                                                                  | | ||||
| | `PathPrefix: /products/, /articles/{category}/{id:[0-9]+}` | Match request prefix path. It accepts a sequence of literal and regular expression prefix paths.                                                                                                                                                                                        | | ||||
| | `PathPrefixStrip: /products/`                              | Match request prefix path and strip off the path prefix prior to forwarding the request to the backend. It accepts a sequence of literal prefix paths. Starting with Traefik 1.3, the stripped prefix path will be available in the `X-Forwarded-Prefix` header.                        | | ||||
| | `PathPrefixStripRegex: /articles/{category}/{id:[0-9]+}`   | Match request prefix path and strip off the path prefix prior to forwarding the request to the backend. It accepts a sequence of literal and regular expression prefix paths. Starting with Traefik 1.3, the stripped prefix path will be available in the `X-Forwarded-Prefix` header. | | ||||
| | `Query: foo=bar, bar=baz`                                  | Match Query String parameters. It accepts a sequence of key=value pairs.                                                                                                                                                                                                                | | ||||
|  | ||||
| In order to use regular expressions with Host and Path matchers, you must declare an arbitrarily named variable followed by the colon-separated regular expression, all enclosed in curly braces. Any pattern supported by [Go's regexp package](https://golang.org/pkg/regexp/) may be used (example: `/posts/{id:[0-9]+}`). | ||||
|  | ||||
| !!! note | ||||
|     The variable has no special meaning; however, it is required by the [gorilla/mux](https://github.com/gorilla/mux) dependency which embeds the regular expression and defines the syntax. | ||||
|  | ||||
| You can optionally enable `passHostHeader` to forward client `Host` header to the backend. | ||||
| You can also optionally enable `passTLSCert` to forward TLS Client certificates to the backend. | ||||
|  | ||||
| ##### Path Matcher Usage Guidelines | ||||
|  | ||||
| This section explains when to use the various path matchers. | ||||
|  | ||||
| Use `Path` if your backend listens on the exact path only. For instance, `Path: /products` would match `/products` but not `/products/shoes`. | ||||
|  | ||||
| Use a `*Prefix*` matcher if your backend listens on a particular base path but also serves requests on sub-paths. | ||||
| For instance, `PathPrefix: /products` would match `/products` but also `/products/shoes` and `/products/shirts`. | ||||
| Since the path is forwarded as-is, your backend is expected to listen on `/products`. | ||||
|  | ||||
| Use a `*Strip` matcher if your backend listens on the root path (`/`) but should be routeable on a specific prefix. | ||||
| For instance, `PathPrefixStrip: /products` would match `/products` but also `/products/shoes` and `/products/shirts`.   | ||||
| Since the path is stripped prior to forwarding, your backend is expected to listen on `/`.   | ||||
| If your backend is serving assets (e.g., images or Javascript files), chances are it must return properly constructed relative URLs.   | ||||
| Continuing on the example, the backend should return `/products/shoes/image.png` (and not `/images.png` which Traefik would likely not be able to associate with the same backend).   | ||||
| The `X-Forwarded-Prefix` header (available since Traefik 1.3) can be queried to build such URLs dynamically. | ||||
|  | ||||
| Instead of distinguishing your backends by path only, you can add a Host matcher to the mix. | ||||
| That way, namespacing of your backends happens on the basis of hosts in addition to paths. | ||||
|  | ||||
| #### Examples | ||||
|  | ||||
| Here is an example of frontends definition: | ||||
|  | ||||
| ```toml | ||||
| [frontends] | ||||
|   [frontends.frontend1] | ||||
|   backend = "backend2" | ||||
|     [frontends.frontend1.routes.test_1] | ||||
|     rule = "Host:test.localhost,test2.localhost" | ||||
|   [frontends.frontend2] | ||||
|   backend = "backend1" | ||||
|   passHostHeader = true | ||||
|   passTLSCert = true | ||||
|   priority = 10 | ||||
|   entrypoints = ["https"] # overrides defaultEntryPoints | ||||
|     [frontends.frontend2.routes.test_1] | ||||
|     rule = "HostRegexp:localhost,{subdomain:[a-z]+}.localhost" | ||||
|   [frontends.frontend3] | ||||
|   backend = "backend2" | ||||
|     [frontends.frontend3.routes.test_1] | ||||
|     rule = "Host:test3.localhost;Path:/test" | ||||
| ``` | ||||
|  | ||||
| - Three frontends are defined: `frontend1`, `frontend2` and `frontend3` | ||||
| - `frontend1` will forward the traffic to the `backend2` if the rule `Host:test.localhost,test2.localhost` is matched | ||||
| - `frontend2` will forward the traffic to the `backend1` if the rule `Host:localhost,{subdomain:[a-z]+}.localhost` is matched (forwarding client `Host` header to the backend) | ||||
| - `frontend3` will forward the traffic to the `backend2` if the rules `Host:test3.localhost` **AND** `Path:/test` are matched | ||||
|  | ||||
| #### Combining multiple rules | ||||
|  | ||||
| As seen in the previous example, you can combine multiple rules. | ||||
| In TOML file, you can use multiple routes: | ||||
|  | ||||
| ```toml | ||||
|   [frontends.frontend3] | ||||
|   backend = "backend2" | ||||
|     [frontends.frontend3.routes.test_1] | ||||
|     rule = "Host:test3.localhost" | ||||
|     [frontends.frontend3.routes.test_2] | ||||
|     rule = "Path:/test" | ||||
| ``` | ||||
|  | ||||
| Here `frontend3` will forward the traffic to the `backend2` if the rules `Host:test3.localhost` **AND** `Path:/test` are matched. | ||||
|  | ||||
| You can also use the notation using a `;` separator, same result: | ||||
|  | ||||
| ```toml | ||||
|   [frontends.frontend3] | ||||
|   backend = "backend2" | ||||
|     [frontends.frontend3.routes.test_1] | ||||
|     rule = "Host:test3.localhost;Path:/test" | ||||
| ``` | ||||
|  | ||||
| Finally, you can create a rule to bind multiple domains or Path to a frontend, using the `,` separator: | ||||
|  | ||||
| ```toml | ||||
|  [frontends.frontend2] | ||||
|     [frontends.frontend2.routes.test_1] | ||||
|     rule = "Host:test1.localhost,test2.localhost" | ||||
|   [frontends.frontend3] | ||||
|   backend = "backend2" | ||||
|     [frontends.frontend3.routes.test_1] | ||||
|     rule = "Path:/test1,/test2" | ||||
| ``` | ||||
|  | ||||
| #### Rules Order | ||||
|  | ||||
| When combining `Modifier` rules with `Matcher` rules, it is important to remember that `Modifier` rules **ALWAYS** apply after the `Matcher` rules. | ||||
|  | ||||
| The following rules are both `Matchers` and `Modifiers`, so the `Matcher` portion of the rule will apply first, and the `Modifier` will apply later. | ||||
|  | ||||
| - `PathStrip` | ||||
| - `PathStripRegex` | ||||
| - `PathPrefixStrip` | ||||
| - `PathPrefixStripRegex` | ||||
|  | ||||
| `Modifiers` will be applied in a pre-determined order regardless of their order in the `rule` configuration section. | ||||
|  | ||||
| 1. `PathStrip` | ||||
| 2. `PathPrefixStrip` | ||||
| 3. `PathStripRegex` | ||||
| 4. `PathPrefixStripRegex` | ||||
| 5. `AddPrefix` | ||||
| 6. `ReplacePath` | ||||
|  | ||||
| #### Priorities | ||||
|  | ||||
| By default, routes will be sorted (in descending order) using rules length (to avoid path overlap): | ||||
| `PathPrefix:/foo;Host:foo.com` (length == 28) will be matched before `PathPrefixStrip:/foobar` (length == 23) will be matched before `PathPrefix:/foo,/bar` (length == 20). | ||||
|  | ||||
| You can customize priority by frontend. The priority value override the rule length during sorting: | ||||
|  | ||||
| ```toml | ||||
|   [frontends] | ||||
|     [frontends.frontend1] | ||||
|     backend = "backend1" | ||||
|     priority = 20 | ||||
|     passHostHeader = true | ||||
|       [frontends.frontend1.routes.test_1] | ||||
|       rule = "PathPrefix:/to" | ||||
|     [frontends.frontend2] | ||||
|     backend = "backend2" | ||||
|     passHostHeader = true | ||||
|       [frontends.frontend2.routes.test_1] | ||||
|       rule = "PathPrefix:/toto" | ||||
| ``` | ||||
|  | ||||
| Here, `frontend1` will be matched before `frontend2` (`20 > 16`). | ||||
|  | ||||
| #### Custom headers | ||||
|  | ||||
| Custom headers can be configured through the frontends, to add headers to either requests or responses that match the frontend's rules. | ||||
| This allows for setting headers such as `X-Script-Name` to be added to the request, or custom headers to be added to the response. | ||||
|  | ||||
| !!! warning | ||||
|     If the custom header name is the same as one header name of the request or response, it will be replaced. | ||||
|  | ||||
| In this example, all matches to the path `/cheese` will have the `X-Script-Name` header added to the proxied request, and the `X-Custom-Response-Header` added to the response. | ||||
|  | ||||
| ```toml | ||||
| [frontends] | ||||
|   [frontends.frontend1] | ||||
|   backend = "backend1" | ||||
|     [frontends.frontend1.headers.customresponseheaders] | ||||
|     X-Custom-Response-Header = "True" | ||||
|     [frontends.frontend1.headers.customrequestheaders] | ||||
|     X-Script-Name = "test" | ||||
|     [frontends.frontend1.routes.test_1] | ||||
|     rule = "PathPrefixStrip:/cheese" | ||||
| ``` | ||||
|  | ||||
| In this second  example, all matches to the path `/cheese` will have the `X-Script-Name` header added to the proxied request, the `X-Custom-Request-Header` removed to the request and the `X-Custom-Response-Header` removed to the response. | ||||
|  | ||||
| ```toml | ||||
| [frontends] | ||||
|   [frontends.frontend1] | ||||
|   backend = "backend1" | ||||
|     [frontends.frontend1.headers.customresponseheaders] | ||||
|     X-Custom-Response-Header = "" | ||||
|     [frontends.frontend1.headers.customrequestheaders] | ||||
|     X-Script-Name = "test" | ||||
|     X-Custom-Request-Header = "" | ||||
|     [frontends.frontend1.routes.test_1] | ||||
|     rule = "PathPrefixStrip:/cheese" | ||||
| ``` | ||||
|  | ||||
| #### Security headers | ||||
|  | ||||
| Security related headers (HSTS headers, SSL redirection, Browser XSS filter, etc) can be added and configured per frontend in a similar manner to the custom headers above. | ||||
| This functionality allows for some easy security features to quickly be set. | ||||
|  | ||||
| An example of some of the security headers: | ||||
|  | ||||
| ```toml | ||||
| [frontends] | ||||
|   [frontends.frontend1] | ||||
|   backend = "backend1" | ||||
|     [frontends.frontend1.headers] | ||||
|     FrameDeny = true | ||||
|     [frontends.frontend1.routes.test_1] | ||||
|     rule = "PathPrefixStrip:/cheddar" | ||||
|   [frontends.frontend2] | ||||
|   backend = "backend2" | ||||
|     [frontends.frontend2.headers] | ||||
|     SSLRedirect = true | ||||
|     [frontends.frontend2.routes.test_1] | ||||
|     rule = "PathPrefixStrip:/stilton" | ||||
| ``` | ||||
|  | ||||
| In this example, traffic routed through the first frontend will have the `X-Frame-Options` header set to `DENY`, and the second will only allow HTTPS request through, otherwise will return a 301 HTTPS redirect. | ||||
|  | ||||
| !!! note | ||||
|     The detailed documentation for those security headers can be found in [unrolled/secure](https://github.com/unrolled/secure#available-options). | ||||
|  | ||||
| ### Backends | ||||
|  | ||||
| A backend is responsible to load-balance the traffic coming from one or more frontends to a set of http servers. | ||||
|  | ||||
| Various methods of load-balancing are supported: | ||||
|  | ||||
| - `wrr`: Weighted Round Robin. | ||||
| - `drr`: Dynamic Round Robin: increases weights on servers that perform better than others. | ||||
|     It also rolls back to original weights if the servers have changed. | ||||
|  | ||||
| A circuit breaker can also be applied to a backend, preventing high loads on failing servers. | ||||
| Initial state is Standby. CB observes the statistics and does not modify the request. | ||||
| In case the condition matches, CB enters Tripped state, where it responds with predefined code or redirects to another frontend. | ||||
| Once Tripped timer expires, CB enters Recovering state and resets all stats. | ||||
| In case the condition does not match and recovery timer expires, CB enters Standby state. | ||||
|  | ||||
| It can be configured using: | ||||
|  | ||||
| - Methods: `LatencyAtQuantileMS`, `NetworkErrorRatio`, `ResponseCodeRatio` | ||||
| - Operators:  `AND`, `OR`, `EQ`, `NEQ`, `LT`, `LE`, `GT`, `GE` | ||||
|  | ||||
| For example: | ||||
|  | ||||
| - `NetworkErrorRatio() > 0.5`: watch error ratio over 10 second sliding window for a frontend. | ||||
| - `LatencyAtQuantileMS(50.0) > 50`:  watch latency at quantile in milliseconds. | ||||
| - `ResponseCodeRatio(500, 600, 0, 600) > 0.5`: ratio of response codes in ranges [500-600) and [0-600). | ||||
|  | ||||
| To proactively prevent backends from being overwhelmed with high load, a maximum connection limit can also be applied to each backend. | ||||
|  | ||||
| Maximum connections can be configured by specifying an integer value for `maxconn.amount` and `maxconn.extractorfunc` which is a strategy used to determine how to categorize requests in order to evaluate the maximum connections. | ||||
|  | ||||
| For example: | ||||
| ```toml | ||||
| [backends] | ||||
|   [backends.backend1] | ||||
|     [backends.backend1.maxconn] | ||||
|        amount = 10 | ||||
|        extractorfunc = "request.host" | ||||
| ``` | ||||
|  | ||||
| - `backend1` will return `HTTP code 429 Too Many Requests` if there are already 10 requests in progress for the same Host header. | ||||
| - Another possible value for `extractorfunc` is `client.ip` which will categorize requests based on client source ip. | ||||
| - Lastly `extractorfunc` can take the value of `request.header.ANY_HEADER` which will categorize requests based on `ANY_HEADER` that you provide. | ||||
|  | ||||
| ### Sticky sessions | ||||
|  | ||||
| Sticky sessions are supported with both load balancers.   | ||||
| When sticky sessions are enabled, a cookie is set on the initial request. | ||||
| The default cookie name is an abbreviation of a sha1 (ex: `_1d52e`). | ||||
| On subsequent requests, the client will be directed to the backend stored in the cookie if it is still healthy. | ||||
| If not, a new backend will be assigned. | ||||
|  | ||||
|  | ||||
| ```toml | ||||
| [backends] | ||||
|   [backends.backend1] | ||||
|     # Enable sticky session | ||||
|     [backends.backend1.loadbalancer.stickiness] | ||||
|  | ||||
|     # Customize the cookie name | ||||
|     # | ||||
|     # Optional | ||||
|     # Default: a sha1 (6 chars) | ||||
|     # | ||||
|     #  cookieName = "my_cookie" | ||||
| ``` | ||||
|  | ||||
| The deprecated way: | ||||
|  | ||||
| ```toml | ||||
| [backends] | ||||
|   [backends.backend1] | ||||
|     [backends.backend1.loadbalancer] | ||||
|       sticky = true | ||||
| ``` | ||||
|  | ||||
| ### Health Check | ||||
|  | ||||
| A health check can be configured in order to remove a backend from LB rotation as long as it keeps returning HTTP status codes other than `200 OK` to HTTP GET requests periodically carried out by Traefik.   | ||||
| The check is defined by a pathappended to the backend URL and an interval (given in a format understood by [time.ParseDuration](https://golang.org/pkg/time/#ParseDuration)) specifying how often the health check should be executed (the default being 30 seconds). | ||||
| Each backend must respond to the health check within 5 seconds.   | ||||
| By default, the port of the backend server is used, however, this may be overridden. | ||||
|  | ||||
| A recovering backend returning 200 OK responses again is being returned to the | ||||
| LB rotation pool. | ||||
|  | ||||
| For example: | ||||
| ```toml | ||||
| [backends] | ||||
|   [backends.backend1] | ||||
|     [backends.backend1.healthcheck] | ||||
|     path = "/health" | ||||
|     interval = "10s" | ||||
| ``` | ||||
|  | ||||
| To use a different port for the healthcheck: | ||||
| ```toml | ||||
| [backends] | ||||
|   [backends.backend1] | ||||
|     [backends.backend1.healthcheck] | ||||
|     path = "/health" | ||||
|     interval = "10s" | ||||
|     port = 8080 | ||||
| ``` | ||||
|  | ||||
| ### Servers | ||||
|  | ||||
| Servers are simply defined using a `url`. You can also apply a custom `weight` to each server (this will be used by load-balancing). | ||||
|  | ||||
| !!! note | ||||
|     Paths in `url` are ignored. Use `Modifier` to specify paths instead. | ||||
|  | ||||
| Here is an example of backends and servers definition: | ||||
|  | ||||
| ```toml | ||||
| [backends] | ||||
|   [backends.backend1] | ||||
|     [backends.backend1.circuitbreaker] | ||||
|     expression = "NetworkErrorRatio() > 0.5" | ||||
|     [backends.backend1.servers.server1] | ||||
|     url = "http://172.17.0.2:80" | ||||
|     weight = 10 | ||||
|     [backends.backend1.servers.server2] | ||||
|     url = "http://172.17.0.3:80" | ||||
|     weight = 1 | ||||
|   [backends.backend2] | ||||
|     [backends.backend2.LoadBalancer] | ||||
|     method = "drr" | ||||
|     [backends.backend2.servers.server1] | ||||
|     url = "http://172.17.0.4:80" | ||||
|     weight = 1 | ||||
|     [backends.backend2.servers.server2] | ||||
|     url = "http://172.17.0.5:80" | ||||
|     weight = 2 | ||||
| ``` | ||||
|  | ||||
| - Two backends are defined: `backend1` and `backend2` | ||||
| - `backend1` will forward the traffic to two servers: `http://172.17.0.2:80"` with weight `10` and `http://172.17.0.3:80` with weight `1` using default `wrr` load-balancing strategy. | ||||
| - `backend2` will forward the traffic to two servers: `http://172.17.0.4:80"` with weight `1` and `http://172.17.0.5:80` with weight `2` using `drr` load-balancing strategy. | ||||
| - a circuit breaker is added on `backend1` using the expression `NetworkErrorRatio() > 0.5`: watch error ratio over 10 second sliding window | ||||
|  | ||||
|  | ||||
| ## Configuration | ||||
|  | ||||
| Træfik's configuration has two parts: | ||||
|  | ||||
| - The [static Træfik configuration](/basics#static-trfik-configuration) which is loaded only at the beginning. | ||||
| - The [dynamic Træfik configuration](/basics#dynamic-trfik-configuration) which can be hot-reloaded (no need to restart the process). | ||||
|  | ||||
| ### Static Træfik configuration | ||||
|  | ||||
| The static configuration is the global configuration which is setting up connections to configuration backends and entrypoints. | ||||
|  | ||||
| Træfik can be configured using many configuration sources with the following precedence order. | ||||
| Each item takes precedence over the item below it: | ||||
|  | ||||
| - [Key-value store](/basics/#key-value-stores) | ||||
| - [Arguments](/basics/#arguments) | ||||
| - [Configuration file](/basics/#configuration-file) | ||||
| - Default | ||||
|  | ||||
| It means that arguments override configuration file, and key-value store overrides arguments. | ||||
|  | ||||
| !!! note | ||||
|     the provider-enabling argument parameters (e.g., `--docker`) set all default values for the specific provider.   | ||||
|     It must not be used if a configuration source with less precedence wants to set a non-default provider value. | ||||
|  | ||||
| #### Configuration file | ||||
|  | ||||
| By default, Træfik will try to find a `traefik.toml` in the following places: | ||||
|  | ||||
| - `/etc/traefik/` | ||||
| - `$HOME/.traefik/` | ||||
| - `.` _the working directory_ | ||||
|  | ||||
| You can override this by setting a `configFile` argument: | ||||
|  | ||||
| ```bash | ||||
| traefik --configFile=foo/bar/myconfigfile.toml | ||||
| ``` | ||||
|  | ||||
| Please refer to the [global configuration](/configuration/commons) section to get documentation on it. | ||||
|  | ||||
| #### Arguments | ||||
|  | ||||
| Each argument (and command) is described in the help section: | ||||
|  | ||||
| ```bash | ||||
| traefik --help | ||||
| ``` | ||||
|  | ||||
| Note that all default values will be displayed as well. | ||||
|  | ||||
| #### Key-value stores | ||||
|  | ||||
| Træfik supports several Key-value stores: | ||||
|  | ||||
| - [Consul](https://consul.io) | ||||
| - [etcd](https://coreos.com/etcd/) | ||||
| - [ZooKeeper](https://zookeeper.apache.org/) | ||||
| - [boltdb](https://github.com/boltdb/bolt) | ||||
|  | ||||
| Please refer to the [User Guide Key-value store configuration](/user-guide/kv-config/) section to get documentation on it. | ||||
|  | ||||
| ### Dynamic Træfik configuration | ||||
|  | ||||
| The dynamic configuration concerns : | ||||
|  | ||||
| - [Frontends](/basics/#frontends) | ||||
| - [Backends](/basics/#backends) | ||||
| - [Servers](/basics/#servers) | ||||
| - HTTPS Certificates | ||||
|  | ||||
| Træfik can hot-reload those rules which could be provided by [multiple configuration backends](/configuration/commons). | ||||
|  | ||||
| We only need to enable `watch` option to make Træfik watch configuration backend changes and generate its configuration automatically. | ||||
| Routes to services will be created and updated instantly at any changes. | ||||
|  | ||||
| Please refer to the [configuration backends](/configuration/commons) section to get documentation on it. | ||||
|  | ||||
| ## Commands | ||||
|  | ||||
| ### traefik | ||||
|  | ||||
| Usage: | ||||
| ```bash | ||||
| traefik [command] [--flag=flag_argument] | ||||
| ``` | ||||
|  | ||||
| List of Træfik available commands with description : | ||||
|  | ||||
| - `version` : Print version | ||||
| - `storeconfig` : Store the static Traefik configuration into a Key-value stores. Please refer to the [Store Træfik configuration](/user-guide/kv-config/#store-configuration-in-key-value-store) section to get documentation on it. | ||||
| - `bug`: The easiest way to submit a pre-filled issue. | ||||
| - `healthcheck`: Calls Traefik `/ping` to check health. | ||||
|  | ||||
| Each command may have related flags. | ||||
|  | ||||
| All those related flags will be displayed with : | ||||
|  | ||||
| ```bash | ||||
| traefik [command] --help | ||||
| ``` | ||||
|  | ||||
| Each command is described at the beginning of the help section: | ||||
|  | ||||
| ```bash | ||||
| traefik --help | ||||
|  | ||||
| # or | ||||
|  | ||||
| docker run traefik[:version] --help | ||||
| # ex: docker run traefik:1.5 --help | ||||
| ``` | ||||
|  | ||||
| ### Command: bug | ||||
|  | ||||
| Here is the easiest way to submit a pre-filled issue on [Træfik GitHub](https://github.com/containous/traefik). | ||||
|  | ||||
| ```bash | ||||
| traefik bug | ||||
| ``` | ||||
|  | ||||
| Watch [this demo](https://www.youtube.com/watch?v=Lyz62L8m93I). | ||||
|  | ||||
| ### Command: healthcheck | ||||
|  | ||||
| This command allows to check the health of Traefik. Its exit status is `0` if Traefik is healthy and `1` if it is unhealthy. | ||||
|  | ||||
| This can be used with Docker [HEALTHCHECK](https://docs.docker.com/engine/reference/builder/#healthcheck) instruction or any other health check orchestration mechanism. | ||||
|  | ||||
| !!! note | ||||
|     The [`ping`](/configuration/ping) must be enabled to allow the `healthcheck` command to call `/ping`. | ||||
|  | ||||
| ```bash | ||||
| traefik healthcheck | ||||
| ``` | ||||
| ```bash | ||||
| OK: http://:8082/ping | ||||
| ``` | ||||
|  | ||||
|  | ||||
| ## Collected Data | ||||
|  | ||||
| **This feature is disabled by default.** | ||||
|  | ||||
| You can read the public proposal on this topic [here](https://github.com/containous/traefik/issues/2369). | ||||
|  | ||||
| ### Why ? | ||||
|  | ||||
| In order to help us learn more about how Træfik is being used and improve it, we collect anonymous usage statistics from running instances. | ||||
| Those data help us prioritize our developments and focus on what's more important (for example, which configuration backend is used and which is not used). | ||||
|  | ||||
| ### What ? | ||||
|  | ||||
| Once a day (the first call begins 10 minutes after the start of Træfik), we collect: | ||||
|  | ||||
| - the Træfik version | ||||
| - a hash of the configuration | ||||
| - an **anonymous version** of the static configuration: | ||||
|     - token, user name, password, URL, IP, domain, email, etc, are removed | ||||
|  | ||||
| !!! note | ||||
|     We do not collect the dynamic configuration (frontends & backends). | ||||
|  | ||||
| !!! note | ||||
|     We do not collect data behind the scenes to run advertising programs or to sell such data to third-party. | ||||
|  | ||||
| #### Here is an example | ||||
|  | ||||
| - Source configuration: | ||||
|  | ||||
| ```toml | ||||
| [entryPoints] | ||||
|     [entryPoints.http] | ||||
|        address = ":80" | ||||
|  | ||||
| [api] | ||||
|  | ||||
| [Docker] | ||||
|   endpoint = "tcp://10.10.10.10:2375" | ||||
|   domain = "foo.bir" | ||||
|   exposedByDefault = true | ||||
|   swarmMode = true | ||||
|  | ||||
|   [Docker.TLS] | ||||
|     CA = "dockerCA" | ||||
|     Cert = "dockerCert" | ||||
|     Key = "dockerKey" | ||||
|     InsecureSkipVerify = true | ||||
|  | ||||
| [ECS] | ||||
|   Domain = "foo.bar" | ||||
|   ExposedByDefault = true | ||||
|   Clusters = ["foo-bar"] | ||||
|   Region = "us-west-2" | ||||
|   AccessKeyID = "AccessKeyID" | ||||
|   SecretAccessKey = "SecretAccessKey" | ||||
| ``` | ||||
|  | ||||
| - Obfuscated and anonymous configuration: | ||||
|  | ||||
| ```toml | ||||
| [entryPoints] | ||||
|     [entryPoints.http] | ||||
|        address = ":80" | ||||
|  | ||||
| [api] | ||||
|  | ||||
| [Docker] | ||||
|   Endpoint = "xxxx" | ||||
|   Domain = "xxxx" | ||||
|   ExposedByDefault = true | ||||
|   SwarmMode = true | ||||
|  | ||||
|   [Docker.TLS] | ||||
|     CA = "xxxx" | ||||
|     Cert = "xxxx" | ||||
|     Key = "xxxx" | ||||
|     InsecureSkipVerify = false | ||||
|  | ||||
| [ECS] | ||||
|   Domain = "xxxx" | ||||
|   ExposedByDefault = true | ||||
|   Clusters = [] | ||||
|   Region = "us-west-2" | ||||
|   AccessKeyID = "xxxx" | ||||
|   SecretAccessKey = "xxxx" | ||||
| ``` | ||||
|  | ||||
| ### Show me the code ! | ||||
|  | ||||
| If you want to dig into more details, here is the source code of the collecting system: [collector.go](https://github.com/containous/traefik/blob/master/collector/collector.go) | ||||
|  | ||||
| By default we anonymize all configuration fields, except fields tagged with `export=true`. | ||||
|  | ||||
| You can check all fields in the [godoc](https://godoc.org/github.com/containous/traefik/configuration#GlobalConfiguration). | ||||
|  | ||||
| ### How to enable this ? | ||||
|  | ||||
| You can enable the collecting system by: | ||||
|  | ||||
| - adding this line in the configuration TOML file: | ||||
|  | ||||
| ```toml | ||||
| # Send anonymous usage data | ||||
| # | ||||
| # Optional | ||||
| # Default: false | ||||
| # | ||||
| sendAnonymousUsage = true | ||||
| ``` | ||||
|  | ||||
| - adding this flag in the CLI: | ||||
|  | ||||
| ```bash | ||||
| ./traefik --sendAnonymousUsage=true | ||||
| ``` | ||||
| @@ -1,214 +0,0 @@ | ||||
| # Benchmarks | ||||
|  | ||||
| ## Configuration | ||||
|  | ||||
| I would like to thanks [vincentbernat](https://github.com/vincentbernat) from [exoscale.ch](https://www.exoscale.ch) who kindly provided the infrastructure needed for the benchmarks. | ||||
|  | ||||
| I used 4 VMs for the tests with the following configuration: | ||||
|  | ||||
| - 32 GB RAM | ||||
| - 8 CPU Cores | ||||
| - 10 GB SSD | ||||
| - Ubuntu 14.04 LTS 64-bit | ||||
|  | ||||
| ## Setup | ||||
|  | ||||
| 1. One VM used to launch the benchmarking tool [wrk](https://github.com/wg/wrk) | ||||
| 2. One VM for Traefik (v1.0.0-beta.416) / nginx (v1.4.6) | ||||
| 3. Two VMs for 2 backend servers in go [whoami](https://github.com/emilevauge/whoamI/) | ||||
|  | ||||
| Each VM has been tuned using the following limits: | ||||
|  | ||||
| ```bash | ||||
| sysctl -w fs.file-max="9999999" | ||||
| sysctl -w fs.nr_open="9999999" | ||||
| sysctl -w net.core.netdev_max_backlog="4096" | ||||
| sysctl -w net.core.rmem_max="16777216" | ||||
| sysctl -w net.core.somaxconn="65535" | ||||
| sysctl -w net.core.wmem_max="16777216" | ||||
| sysctl -w net.ipv4.ip_local_port_range="1025       65535" | ||||
| sysctl -w net.ipv4.tcp_fin_timeout="30" | ||||
| sysctl -w net.ipv4.tcp_keepalive_time="30" | ||||
| sysctl -w net.ipv4.tcp_max_syn_backlog="20480" | ||||
| sysctl -w net.ipv4.tcp_max_tw_buckets="400000" | ||||
| sysctl -w net.ipv4.tcp_no_metrics_save="1" | ||||
| sysctl -w net.ipv4.tcp_syn_retries="2" | ||||
| sysctl -w net.ipv4.tcp_synack_retries="2" | ||||
| sysctl -w net.ipv4.tcp_tw_recycle="1" | ||||
| sysctl -w net.ipv4.tcp_tw_reuse="1" | ||||
| sysctl -w vm.min_free_kbytes="65536" | ||||
| sysctl -w vm.overcommit_memory="1" | ||||
| ulimit -n 9999999 | ||||
| ``` | ||||
|  | ||||
| ### Nginx | ||||
|  | ||||
| Here is the config Nginx file use `/etc/nginx/nginx.conf`: | ||||
|  | ||||
| ``` | ||||
| user www-data; | ||||
| worker_processes auto; | ||||
| worker_rlimit_nofile 200000; | ||||
| pid /var/run/nginx.pid; | ||||
|  | ||||
| events { | ||||
|     worker_connections 10000; | ||||
|     use epoll; | ||||
|     multi_accept on; | ||||
| } | ||||
|  | ||||
| http { | ||||
|     sendfile on; | ||||
|     tcp_nopush on; | ||||
|     tcp_nodelay on; | ||||
|     keepalive_timeout 300; | ||||
|     keepalive_requests 10000; | ||||
|     types_hash_max_size 2048; | ||||
|  | ||||
|     open_file_cache max=200000 inactive=300s; | ||||
|     open_file_cache_valid 300s; | ||||
|     open_file_cache_min_uses 2; | ||||
|     open_file_cache_errors on; | ||||
|  | ||||
|     server_tokens off; | ||||
|     dav_methods off; | ||||
|  | ||||
|     include /etc/nginx/mime.types; | ||||
|     default_type application/octet-stream; | ||||
|  | ||||
|     access_log /var/log/nginx/access.log combined; | ||||
|     error_log /var/log/nginx/error.log warn; | ||||
|  | ||||
|     gzip off; | ||||
|     gzip_vary off; | ||||
|  | ||||
|     include /etc/nginx/conf.d/*.conf; | ||||
|     include /etc/nginx/sites-enabled/*.conf; | ||||
| } | ||||
| ``` | ||||
|  | ||||
| Here is the Nginx vhost file used: | ||||
|  | ||||
| ``` | ||||
| upstream whoami { | ||||
|     server IP-whoami1:80; | ||||
|     server IP-whoami2:80; | ||||
|     keepalive 300; | ||||
| } | ||||
|  | ||||
| server { | ||||
|     listen 8001; | ||||
|     server_name test.traefik; | ||||
|     access_log off; | ||||
|     error_log /dev/null crit; | ||||
|     if ($host != "test.traefik") { | ||||
|         return 404; | ||||
|     } | ||||
|     location / { | ||||
|         proxy_pass http://whoami; | ||||
|         proxy_http_version 1.1; | ||||
|         proxy_set_header Connection ""; | ||||
| 	proxy_set_header  X-Forwarded-Host $host; | ||||
|     } | ||||
| } | ||||
| ``` | ||||
|  | ||||
| ### Traefik | ||||
|  | ||||
| Here is the `traefik.toml` file used: | ||||
|  | ||||
| ```toml | ||||
| MaxIdleConnsPerHost = 100000 | ||||
| defaultEntryPoints = ["http"] | ||||
|  | ||||
| [entryPoints] | ||||
|   [entryPoints.http] | ||||
|   address = ":8000" | ||||
|  | ||||
| [file] | ||||
| [backends] | ||||
|   [backends.backend1] | ||||
|     [backends.backend1.servers.server1] | ||||
|     url = "http://IP-whoami1:80" | ||||
|     weight = 1 | ||||
|     [backends.backend1.servers.server2] | ||||
|     url = "http://IP-whoami2:80" | ||||
|     weight = 1 | ||||
|  | ||||
| [frontends] | ||||
|   [frontends.frontend1] | ||||
|   backend = "backend1" | ||||
|     [frontends.frontend1.routes.test_1] | ||||
|     rule = "Host: test.traefik" | ||||
| ``` | ||||
|  | ||||
| ## Results | ||||
|  | ||||
| ### whoami: | ||||
| ```shell | ||||
| wrk -t20 -c1000 -d60s -H "Host: test.traefik" --latency  http://IP-whoami:80/bench | ||||
| Running 1m test @ http://IP-whoami:80/bench | ||||
|   20 threads and 1000 connections | ||||
|   Thread Stats   Avg      Stdev     Max   +/- Stdev | ||||
|     Latency    70.28ms  134.72ms   1.91s    89.94% | ||||
|     Req/Sec     2.92k   742.42     8.78k    68.80% | ||||
|   Latency Distribution | ||||
|      50%   10.63ms | ||||
|      75%   75.64ms | ||||
|      90%  205.65ms | ||||
|      99%  668.28ms | ||||
|   3476705 requests in 1.00m, 384.61MB read | ||||
|   Socket errors: connect 0, read 0, write 0, timeout 103 | ||||
| Requests/sec:  57894.35 | ||||
| Transfer/sec:      6.40MB | ||||
| ``` | ||||
|  | ||||
| ### nginx: | ||||
| ```shell | ||||
| wrk -t20 -c1000 -d60s -H "Host: test.traefik" --latency  http://IP-nginx:8001/bench | ||||
| Running 1m test @ http://IP-nginx:8001/bench | ||||
|   20 threads and 1000 connections | ||||
|   Thread Stats   Avg      Stdev     Max   +/- Stdev | ||||
|     Latency   101.25ms  180.09ms   1.99s    89.34% | ||||
|     Req/Sec     1.69k   567.69     9.39k    72.62% | ||||
|   Latency Distribution | ||||
|      50%   15.46ms | ||||
|      75%  129.11ms | ||||
|      90%  302.44ms | ||||
|      99%  846.59ms | ||||
|   2018427 requests in 1.00m, 298.36MB read | ||||
|   Socket errors: connect 0, read 0, write 0, timeout 90 | ||||
| Requests/sec:  33591.67 | ||||
| Transfer/sec:      4.97MB | ||||
| ``` | ||||
|  | ||||
| ### Traefik: | ||||
|  | ||||
| ```shell | ||||
| wrk -t20 -c1000 -d60s -H "Host: test.traefik" --latency  http://IP-traefik:8000/bench | ||||
| Running 1m test @ http://IP-traefik:8000/bench | ||||
|   20 threads and 1000 connections | ||||
|   Thread Stats   Avg      Stdev     Max   +/- Stdev | ||||
|     Latency    91.72ms  150.43ms   2.00s    90.50% | ||||
|     Req/Sec     1.43k   266.37     2.97k    69.77% | ||||
|   Latency Distribution | ||||
|      50%   19.74ms | ||||
|      75%  121.98ms | ||||
|      90%  237.39ms | ||||
|      99%  687.49ms | ||||
|   1705073 requests in 1.00m, 188.63MB read | ||||
|   Socket errors: connect 0, read 0, write 0, timeout 7 | ||||
| Requests/sec:  28392.44 | ||||
| Transfer/sec:      3.14MB | ||||
| ``` | ||||
|  | ||||
| ## Conclusion | ||||
|  | ||||
| Traefik is obviously slower than Nginx, but not so much: Traefik can serve 28392 requests/sec and Nginx 33591 requests/sec which gives a ratio of 85%. | ||||
| Not bad for young project :) ! | ||||
|  | ||||
| Some areas of possible improvements: | ||||
|  | ||||
| - Use [GO_REUSEPORT](https://github.com/kavu/go_reuseport) listener | ||||
| - Run a separate server instance per CPU core with `GOMAXPROCS=1` (it appears during benchmarks that there is a lot more context switches with Traefik than with nginx) | ||||
|  | ||||
							
								
								
									
										43
									
								
								docs/check.Dockerfile
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										43
									
								
								docs/check.Dockerfile
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,43 @@ | ||||
| FROM alpine:3.20 | ||||
|  | ||||
| RUN apk --no-cache --no-progress add \ | ||||
|     build-base \ | ||||
|     gcompat \ | ||||
|     libcurl \ | ||||
|     libxml2-dev \ | ||||
|     libxslt-dev \ | ||||
|     ruby \ | ||||
|     ruby-bigdecimal \ | ||||
|     ruby-dev \ | ||||
|     ruby-etc \ | ||||
|     ruby-ffi \ | ||||
|     ruby-json \ | ||||
|     zlib-dev | ||||
|  | ||||
| RUN gem install nokogiri --version 1.15.3 --no-document -- --use-system-libraries | ||||
| RUN gem install html-proofer --version 5.0.7 --no-document -- --use-system-libraries | ||||
|  | ||||
| # After Ruby, some NodeJS YAY! | ||||
| RUN apk --no-cache --no-progress add \ | ||||
|     git \ | ||||
|     nodejs \ | ||||
|     npm | ||||
|  | ||||
| RUN npm install --global \ | ||||
|     markdownlint@0.29.0 \ | ||||
|     markdownlint-cli@0.35.0 | ||||
|  | ||||
| # Finally the shell tools we need for later | ||||
| # tini helps to terminate properly all the parallelized tasks when sending CTRL-C | ||||
| RUN apk --no-cache --no-progress add \ | ||||
|     ca-certificates \ | ||||
|     curl \ | ||||
|     tini | ||||
|  | ||||
| COPY ./scripts/verify.sh /verify.sh | ||||
| COPY ./scripts/lint.sh /lint.sh | ||||
|  | ||||
| WORKDIR /app | ||||
| VOLUME ["/tmp","/app"] | ||||
|  | ||||
| ENTRYPOINT ["/sbin/tini","-g","sh"] | ||||
| @@ -1,462 +0,0 @@ | ||||
| # ACME (Let's Encrypt) configuration | ||||
|  | ||||
| See also [Let's Encrypt examples](/user-guide/examples/#lets-encrypt-support) and [Docker & Let's Encrypt user guide](/user-guide/docker-and-lets-encrypt). | ||||
|  | ||||
| ## Configuration | ||||
|  | ||||
| ```toml | ||||
| # Sample entrypoint configuration when using ACME. | ||||
| [entryPoints] | ||||
|   [entryPoints.http] | ||||
|   address = ":80" | ||||
|   [entryPoints.https] | ||||
|   address = ":443" | ||||
|     [entryPoints.https.tls] | ||||
| ``` | ||||
|  | ||||
| ```toml | ||||
| # Enable ACME (Let's Encrypt): automatic SSL. | ||||
| [acme] | ||||
|  | ||||
| # Email address used for registration. | ||||
| # | ||||
| # Required | ||||
| # | ||||
| email = "test@traefik.io" | ||||
|  | ||||
| # File used for certificates storage. | ||||
| # | ||||
| # Optional (Deprecated) | ||||
| # | ||||
| #storageFile = "acme.json" | ||||
|  | ||||
| # File or key used for certificates storage. | ||||
| # | ||||
| # Required | ||||
| # | ||||
| storage = "acme.json" | ||||
| # or `storage = "traefik/acme/account"` if using KV store. | ||||
|  | ||||
| # Entrypoint to proxy acme apply certificates to. | ||||
| # | ||||
| # Required | ||||
| # | ||||
| entryPoint = "https" | ||||
|  | ||||
| # Deprecated, replaced by [acme.dnsChallenge]. | ||||
| # | ||||
| # Optional. | ||||
| # | ||||
| # dnsProvider = "digitalocean" | ||||
|  | ||||
| # Deprecated, replaced by [acme.dnsChallenge.delayBeforeCheck]. | ||||
| # | ||||
| # Optional | ||||
| # Default: 0 | ||||
| # | ||||
| # delayDontCheckDNS = 0 | ||||
|  | ||||
| # If true, display debug log messages from the acme client library. | ||||
| # | ||||
| # Optional | ||||
| # Default: false | ||||
| # | ||||
| # acmeLogging = true | ||||
|  | ||||
| # Enable on demand certificate generation. | ||||
| # | ||||
| # Optional (Deprecated) | ||||
| # Default: false | ||||
| # | ||||
| # onDemand = true | ||||
|  | ||||
| # Enable certificate generation on frontends Host rules. | ||||
| # | ||||
| # Optional | ||||
| # Default: false | ||||
| # | ||||
| # onHostRule = true | ||||
|  | ||||
| # CA server to use. | ||||
| # - Uncomment the line to run on the staging let's encrypt server. | ||||
| # - Leave comment to go to prod. | ||||
| # | ||||
| # Optional | ||||
| # Default: "https://acme-v02.api.letsencrypt.org/directory" | ||||
| # | ||||
| # caServer = "https://acme-staging-v02.api.letsencrypt.org/directory" | ||||
|  | ||||
| # Domains list. | ||||
| # Only domains defined here can generate wildcard certificates. | ||||
| # | ||||
| # [[acme.domains]] | ||||
| #   main = "local1.com" | ||||
| #   sans = ["test1.local1.com", "test2.local1.com"] | ||||
| # [[acme.domains]] | ||||
| #   main = "local2.com" | ||||
| #   sans = ["test1.local2.com", "test2.local2.com"] | ||||
| # [[acme.domains]] | ||||
| #   main = "local3.com" | ||||
| # [[acme.domains]] | ||||
| #   main = "local4.com" | ||||
|  | ||||
| # Use a HTTP-01 acme challenge. | ||||
| # | ||||
| # Optional but recommend | ||||
| # | ||||
| [acme.httpChallenge] | ||||
|  | ||||
|   # EntryPoint to use for the HTTP-01 challenges. | ||||
|   # | ||||
|   # Required | ||||
|   # | ||||
|   entryPoint = "http" | ||||
|  | ||||
| # Use a DNS-01/DNS-02 acme challenge rather than HTTP-01 challenge. | ||||
| # Note : Mandatory for wildcard certificates generation. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| # [acme.dnsChallenge] | ||||
|  | ||||
|   # Provider used. | ||||
|   # | ||||
|   # Required | ||||
|   # | ||||
|   # provider = "digitalocean" | ||||
|  | ||||
|   # By default, the provider will verify the TXT DNS challenge record before letting ACME verify. | ||||
|   # If delayBeforeCheck is greater than zero, avoid this & instead just wait so many seconds. | ||||
|   # Useful if internal networks block external DNS queries. | ||||
|   # | ||||
|   # Optional | ||||
|   # Default: 0 | ||||
|   # | ||||
|   # delayBeforeCheck = 0 | ||||
| ``` | ||||
|  | ||||
| !!! note | ||||
|     If `HTTP-01` challenge is used, `acme.httpChallenge.entryPoint` has to be defined and reachable by Let's Encrypt through the port 80. | ||||
|     These are Let's Encrypt limitations as described on the [community forum](https://community.letsencrypt.org/t/support-for-ports-other-than-80-and-443/3419/72). | ||||
|  | ||||
| !!! note | ||||
|     Wildcard certificates can be generated only if `acme.dnsChallenge` | ||||
| option is enable. | ||||
|  | ||||
| ### Let's Encrypt downtime | ||||
|  | ||||
| Let's Encrypt functionality will be limited until Træfik is restarted. | ||||
|  | ||||
| If Let's Encrypt is not reachable, these certificates will be used : | ||||
|  | ||||
|   - ACME certificates already generated before downtime | ||||
|   - Expired ACME certificates | ||||
|   - Provided certificates | ||||
|  | ||||
| !!! note | ||||
|     Default Træfik certificate will be used instead of ACME certificates for new (sub)domains (which need Let's Encrypt challenge). | ||||
|  | ||||
| ### `storage` | ||||
|  | ||||
| ```toml | ||||
| [acme] | ||||
| # ... | ||||
| storage = "acme.json" | ||||
| # ... | ||||
| ``` | ||||
|  | ||||
| The `storage` option sets where are stored your ACME certificates. | ||||
|  | ||||
| There are two kind of `storage` : | ||||
|  | ||||
| - a JSON file, | ||||
| - a KV store entry. | ||||
|  | ||||
| !!! danger "DEPRECATED" | ||||
|     `storage` replaces `storageFile` which is deprecated. | ||||
|  | ||||
| !!! note | ||||
|     During Træfik configuration migration from a configuration file to a KV store (thanks to `storeconfig` subcommand as described [here](/user-guide/kv-config/#store-configuration-in-key-value-store)), if ACME certificates have to be migrated too, use both `storageFile` and `storage`. | ||||
|  | ||||
|     - `storageFile` will contain the path to the `acme.json` file to migrate. | ||||
|     - `storage` will contain the key where the certificates will be stored. | ||||
|  | ||||
| #### Store data in a file | ||||
|  | ||||
| ACME certificates can be stored in a JSON file which with the `600` right mode. | ||||
|  | ||||
| There are two ways to store ACME certificates in a file from Docker: | ||||
|  | ||||
| - create a file on your host and mount it as a volume: | ||||
| ```toml | ||||
| storage = "acme.json" | ||||
| ``` | ||||
| ```bash | ||||
| docker run -v "/my/host/acme.json:acme.json" traefik | ||||
| ``` | ||||
| - mount the folder containing the file as a volume | ||||
| ```toml | ||||
| storage = "/etc/traefik/acme/acme.json" | ||||
| ``` | ||||
| ```bash | ||||
| docker run -v "/my/host/acme:/etc/traefik/acme" traefik | ||||
| ``` | ||||
|  | ||||
| !!! warning | ||||
|     This file cannot be shared per many instances of Træfik at the same time. | ||||
|     If you have to use Træfik cluster mode, please use [a KV Store entry](/configuration/acme/#storage-kv-entry). | ||||
|  | ||||
| #### Store data in a KV store entry | ||||
|  | ||||
| ACME certificates can be stored in a KV Store entry. | ||||
|  | ||||
| ```toml | ||||
| storage = "traefik/acme/account" | ||||
| ``` | ||||
|  | ||||
| **This kind of storage is mandatory in cluster mode.** | ||||
|  | ||||
| Because KV stores (like Consul) have limited entries size, the certificates list is compressed before to be set in a KV store entry. | ||||
|  | ||||
| !!! note | ||||
|     It's possible to store up to approximately 100 ACME certificates in Consul. | ||||
|  | ||||
| ### `httpChallenge` | ||||
|  | ||||
| Use `HTTP-01` challenge to generate/renew ACME certificates. | ||||
|  | ||||
| The redirection is fully compatible with the HTTP-01 challenge. | ||||
| You can use redirection with HTTP-01 challenge without problem. | ||||
|  | ||||
| ```toml | ||||
| [acme] | ||||
| # ... | ||||
| entryPoint = "https" | ||||
| [acme.httpChallenge] | ||||
|   entryPoint = "http" | ||||
| ``` | ||||
|  | ||||
| #### `entryPoint` | ||||
|  | ||||
| Specify the entryPoint to use during the challenges. | ||||
|  | ||||
| ```toml | ||||
| defaultEntryPoints = ["http", "https"] | ||||
|  | ||||
| [entryPoints] | ||||
|   [entryPoints.http] | ||||
|   address = ":80" | ||||
|   [entryPoints.https] | ||||
|   address = ":443" | ||||
|     [entryPoints.https.tls] | ||||
| # ... | ||||
|  | ||||
| [acme] | ||||
|   # ... | ||||
|   entryPoint = "https" | ||||
|   [acme.httpChallenge] | ||||
|     entryPoint = "http" | ||||
| ``` | ||||
|  | ||||
| !!! note | ||||
|     `acme.httpChallenge.entryPoint` has to be reachable by Let's Encrypt through the port 80. | ||||
|     It's a Let's Encrypt limitation as described on the [community forum](https://community.letsencrypt.org/t/support-for-ports-other-than-80-and-443/3419/72). | ||||
|  | ||||
| ### `dnsChallenge` | ||||
|  | ||||
| Use `DNS-01/DNS-02` challenge to generate/renew ACME certificates. | ||||
|  | ||||
| ```toml | ||||
| [acme] | ||||
| # ... | ||||
| [acme.dnsChallenge] | ||||
|   provider = "digitalocean" | ||||
|   delayBeforeCheck = 0 | ||||
| # ... | ||||
| ``` | ||||
|  | ||||
| !!! note | ||||
|     ACME wildcard certificates can only be generated thanks to a `DNS-02` challenge. | ||||
|  | ||||
| #### `provider` | ||||
|  | ||||
| Select the provider that matches the DNS domain that will host the challenge TXT record, and provide environment variables to enable setting it: | ||||
|  | ||||
| | Provider Name                                          | Provider code  | Configuration                                                                                                             | | ||||
| |--------------------------------------------------------|----------------|---------------------------------------------------------------------------------------------------------------------------| | ||||
| | [Auroradns](https://www.pcextreme.com/aurora/dns)      | `auroradns`    | `AURORA_USER_ID`, `AURORA_KEY`, `AURORA_ENDPOINT`                                                                         | | ||||
| | [Azure](https://azure.microsoft.com/services/dns/)     | `azure`        | `AZURE_CLIENT_ID`, `AZURE_CLIENT_SECRET`, `AZURE_SUBSCRIPTION_ID`, `AZURE_TENANT_ID`, `AZURE_RESOURCE_GROUP`              | | ||||
| | [Cloudflare](https://www.cloudflare.com)               | `cloudflare`   | `CLOUDFLARE_EMAIL`, `CLOUDFLARE_API_KEY` - The Cloudflare `Global API Key` needs to be used and not the `Origin CA Key`   | | ||||
| | [CloudXNS](https://www.cloudxns.net)                   | `cloudxns`     | `CLOUDXNS_API_KEY`, `CLOUDXNS_SECRET_KEY`                                                                                 | | ||||
| | [DigitalOcean](https://www.digitalocean.com)           | `digitalocean` | `DO_AUTH_TOKEN`                                                                                                           | | ||||
| | [DNSimple](https://dnsimple.com)                       | `dnsimple`     | `DNSIMPLE_OAUTH_TOKEN`, `DNSIMPLE_BASE_URL`                                                                               | | ||||
| | [DNS Made Easy](https://dnsmadeeasy.com)               | `dnsmadeeasy`  | `DNSMADEEASY_API_KEY`, `DNSMADEEASY_API_SECRET`, `DNSMADEEASY_SANDBOX`                                                    | | ||||
| | [DNSPod](http://www.dnspod.net/)                       | `dnspod`       | `DNSPOD_API_KEY`                                                                                                          | | ||||
| | [Dyn](https://dyn.com)                                 | `dyn`          | `DYN_CUSTOMER_NAME`, `DYN_USER_NAME`, `DYN_PASSWORD`                                                                      | | ||||
| | [Exoscale](https://www.exoscale.ch)                    | `exoscale`     | `EXOSCALE_API_KEY`, `EXOSCALE_API_SECRET`, `EXOSCALE_ENDPOINT`                                                            | | ||||
| | [Gandi](https://www.gandi.net)                         | `gandi`        | `GANDI_API_KEY`                                                                                                           | | ||||
| | [Gandi V5](http://doc.livedns.gandi.net)               | `gandiv5`      | `GANDIV5_API_KEY`                                                                                                         | | ||||
| | [GoDaddy](https://godaddy.com/domains)                 | `godaddy`      | `GODADDY_API_KEY`, `GODADDY_API_SECRET`                                                                                   | | ||||
| | [Google Cloud DNS](https://cloud.google.com/dns/docs/) | `gcloud`       | `GCE_PROJECT`, `GCE_SERVICE_ACCOUNT_FILE`                                                                                 | | ||||
| | [Linode](https://www.linode.com)                       | `linode`       | `LINODE_API_KEY`                                                                                                          | | ||||
| | manual                                                 | -              | none, but run Træfik interactively & turn on `acmeLogging` to see instructions & press <kbd>Enter</kbd>.                  | | ||||
| | [Namecheap](https://www.namecheap.com)                 | `namecheap`    | `NAMECHEAP_API_USER`, `NAMECHEAP_API_KEY`                                                                                 | | ||||
| | [Ns1](https://ns1.com/)                                | `ns1`          | `NS1_API_KEY`                                                                                                             | | ||||
| | [Open Telekom Cloud](https://cloud.telekom.de/en/)     | `otc`          | `OTC_DOMAIN_NAME`, `OTC_USER_NAME`, `OTC_PASSWORD`, `OTC_PROJECT_NAME`, `OTC_IDENTITY_ENDPOINT`                           | | ||||
| | [OVH](https://www.ovh.com)                             | `ovh`          | `OVH_ENDPOINT`, `OVH_APPLICATION_KEY`, `OVH_APPLICATION_SECRET`, `OVH_CONSUMER_KEY`                                       | | ||||
| | [PowerDNS](https://www.powerdns.com)                   | `pdns`         | `PDNS_API_KEY`, `PDNS_API_URL`                                                                                            | | ||||
| | [Rackspace](https://www.rackspace.com/cloud/dns)       | `rackspace`    | `RACKSPACE_USER`, `RACKSPACE_API_KEY`                                                                                     | | ||||
| | [RFC2136](https://tools.ietf.org/html/rfc2136)         | `rfc2136`      | `RFC2136_TSIG_KEY`, `RFC2136_TSIG_SECRET`, `RFC2136_TSIG_ALGORITHM`, `RFC2136_NAMESERVER`                                 | | ||||
| | [Route 53](https://aws.amazon.com/route53/)            | `route53`      | `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_REGION`, `AWS_HOSTED_ZONE_ID` or configured user/instance IAM profile. | | ||||
| | [VULTR](https://www.vultr.com)                         | `vultr`        | `VULTR_API_KEY`                                                                                                           | | ||||
|  | ||||
| #### `delayBeforeCheck` | ||||
|  | ||||
| By default, the `provider` will verify the TXT DNS challenge record before letting ACME verify.   | ||||
| If `delayBeforeCheck` is greater than zero, avoid this & instead just wait so many seconds. | ||||
|  | ||||
| Useful if internal networks block external DNS queries. | ||||
|  | ||||
| !!! note | ||||
|     This field has no sense if a `provider` is not defined. | ||||
|  | ||||
| ### `onDemand` (Deprecated) | ||||
|  | ||||
| !!! danger "DEPRECATED" | ||||
|     This option is deprecated. | ||||
|  | ||||
| ```toml | ||||
| [acme] | ||||
| # ... | ||||
| onDemand = true | ||||
| # ... | ||||
| ``` | ||||
|  | ||||
| Enable on demand certificate. | ||||
|  | ||||
| This will request a certificate from Let's Encrypt during the first TLS handshake for a host name that does not yet have a certificate. | ||||
|  | ||||
| !!! warning | ||||
|     TLS handshakes will be slow when requesting a host name certificate for the first time, this can lead to DoS attacks. | ||||
|  | ||||
| !!! warning | ||||
|     Take note that Let's Encrypt have [rate limiting](https://letsencrypt.org/docs/rate-limits). | ||||
|  | ||||
| ### `onHostRule` | ||||
|  | ||||
| ```toml | ||||
| [acme] | ||||
| # ... | ||||
| onHostRule = true | ||||
| # ... | ||||
| ``` | ||||
|  | ||||
| Enable certificate generation on frontends `Host` rules (for frontends wired on the `acme.entryPoint`). | ||||
|  | ||||
| This will request a certificate from Let's Encrypt for each frontend with a Host rule. | ||||
|  | ||||
| For example, a rule `Host:test1.traefik.io,test2.traefik.io` will request a certificate with main domain `test1.traefik.io` and SAN `test2.traefik.io`. | ||||
|  | ||||
| !!! warning | ||||
|     `onHostRule` option can not be used to generate wildcard certificates. | ||||
|     Refer to [the wildcard generation section](/configuration/acme/#wildcard-domain) for more information. | ||||
|  | ||||
| ### `caServer` | ||||
|  | ||||
| ```toml | ||||
| [acme] | ||||
| # ... | ||||
| caServer = "https://acme-staging-v02.api.letsencrypt.org/directory" | ||||
| # ... | ||||
| ``` | ||||
|  | ||||
| CA server to use. | ||||
|  | ||||
| - Uncomment the line to run on the staging Let's Encrypt server. | ||||
| - Leave comment to go to prod. | ||||
|  | ||||
| ### `domains` | ||||
|  | ||||
| ```toml | ||||
| [acme] | ||||
| # ... | ||||
| [[acme.domains]] | ||||
|   main = "local1.com" | ||||
|   sans = ["test1.local1.com", "test2.local1.com"] | ||||
| [[acme.domains]] | ||||
|   main = "local2.com" | ||||
|   sans = ["test1.local2.com", "test2.local2.com"] | ||||
| [[acme.domains]] | ||||
|   main = "local3.com" | ||||
| [[acme.domains]] | ||||
|   main = "*.local4.com" | ||||
| # ... | ||||
| ``` | ||||
|  | ||||
| #### Wildcard domains | ||||
|  | ||||
| Wildcard domain has to be defined as a main domain **with no SANs** (alternative domains). | ||||
| All domains must have A/AAAA records pointing to Træfik. | ||||
|  | ||||
| !!! warning | ||||
|     Note that Let's Encrypt has [rate limiting](https://letsencrypt.org/docs/rate-limits). | ||||
|  | ||||
| Each domain & SANs will lead to a certificate request. | ||||
|  | ||||
| #### Others domains | ||||
|  | ||||
| You can provide SANs (alternative domains) to each main domain. | ||||
| All domains must have A/AAAA records pointing to Træfik. | ||||
|  | ||||
| !!! warning | ||||
|     Take note that Let's Encrypt have [rate limiting](https://letsencrypt.org/docs/rate-limits). | ||||
|  | ||||
| Each domain & SANs will lead to a certificate request. | ||||
|  | ||||
| ### `dnsProvider` (Deprecated) | ||||
|  | ||||
| !!! danger "DEPRECATED" | ||||
|     This option is deprecated, use [dnsChallenge.provider](/configuration/acme/#dnschallenge) instead. | ||||
|  | ||||
| ### `delayDontCheckDNS` (Deprecated) | ||||
|  | ||||
| !!! danger "DEPRECATED" | ||||
|     This option is deprecated, use [dnsChallenge.delayBeforeCheck](/configuration/acme/#dnschallenge) instead. | ||||
|  | ||||
| ## Wildcard certificates | ||||
|  | ||||
| [ACME V2](https://community.letsencrypt.org/t/acme-v2-and-wildcard-certificate-support-is-live/55579) allows wildcard certificate support. | ||||
| However, this feature needs a specific configuration. | ||||
|  | ||||
| ### DNS-02 Challenge | ||||
|  | ||||
| As described in [Let's Encrypt post](https://community.letsencrypt.org/t/staging-endpoint-for-acme-v2/49605), wildcard certificates can only be generated through a `DNS-02`Challenge. | ||||
| This challenge is linked to the Træfik option `acme.dnsChallenge`. | ||||
|  | ||||
| ```toml | ||||
| [acme] | ||||
| # ... | ||||
| [acme.dnsChallenge] | ||||
|   provider = "digitalocean" | ||||
|   delayBeforeCheck = 0 | ||||
| # ... | ||||
| ``` | ||||
|  | ||||
| For more information about this option, please refer to the [dnsChallenge section](/configuration/acme/#dnschallenge). | ||||
|  | ||||
| ### Wildcard domain | ||||
|  | ||||
| Wildcard domains can currently be provided only by to the `acme.domains` option. | ||||
| Theses domains can not have SANs. | ||||
|  | ||||
| ```toml | ||||
| [acme] | ||||
| # ... | ||||
| [[acme.domains]] | ||||
|   main = "*local1.com" | ||||
| [[acme.domains]] | ||||
|   main = "*.local2.com" | ||||
| # ... | ||||
| ``` | ||||
|  | ||||
| For more information about this option, please refer to the [domains section](/configuration/acme/#domains). | ||||
| @@ -1,328 +0,0 @@ | ||||
| # API Definition | ||||
|  | ||||
| ## Configuration | ||||
|  | ||||
| ```toml | ||||
| # API definition | ||||
| [api] | ||||
|   # Name of the related entry point | ||||
|   # | ||||
|   # Optional | ||||
|   # Default: "traefik" | ||||
|   # | ||||
|   entryPoint = "traefik" | ||||
|  | ||||
|   # Enabled Dashboard | ||||
|   # | ||||
|   # Optional | ||||
|   # Default: true | ||||
|   # | ||||
|   dashboard = true | ||||
|  | ||||
|   # Enable debug mode. | ||||
|   # This will install HTTP handlers to expose Go expvars under /debug/vars and | ||||
|   # pprof profiling data under /debug/pprof. | ||||
|   # Additionally, the log level will be set to DEBUG. | ||||
|   # | ||||
|   # Optional | ||||
|   # Default: false | ||||
|   # | ||||
|   debug = true | ||||
| ``` | ||||
|  | ||||
| For more customization, see [entry points](/configuration/entrypoints/) documentation and [examples](/user-guide/examples/#ping-health-check). | ||||
|  | ||||
| ## Web UI | ||||
|  | ||||
|  | ||||
|  | ||||
|  | ||||
|  | ||||
| ## API | ||||
|  | ||||
| | Path                                                            | Method           | Description                               | | ||||
| |-----------------------------------------------------------------|------------------|-------------------------------------------| | ||||
| | `/`                                                             |     `GET`        | Provides a simple HTML frontend of Træfik | | ||||
| | `/cluster/leader`                                               |     `GET`        | JSON leader true/false response           | | ||||
| | `/health`                                                       |     `GET`        | JSON health metrics                       | | ||||
| | `/api`                                                          |     `GET`        | Configuration for all providers           | | ||||
| | `/api/providers`                                                |     `GET`        | Providers                                 | | ||||
| | `/api/providers/{provider}`                                     |     `GET`, `PUT` | Get or update provider (1)                | | ||||
| | `/api/providers/{provider}/backends`                            |     `GET`        | List backends                             | | ||||
| | `/api/providers/{provider}/backends/{backend}`                  |     `GET`        | Get backend                               | | ||||
| | `/api/providers/{provider}/backends/{backend}/servers`          |     `GET`        | List servers in backend                   | | ||||
| | `/api/providers/{provider}/backends/{backend}/servers/{server}` |     `GET`        | Get a server in a backend                 | | ||||
| | `/api/providers/{provider}/frontends`                           |     `GET`        | List frontends                            | | ||||
| | `/api/providers/{provider}/frontends/{frontend}`                |     `GET`        | Get a frontend                            | | ||||
| | `/api/providers/{provider}/frontends/{frontend}/routes`         |     `GET`        | List routes in a frontend                 | | ||||
| | `/api/providers/{provider}/frontends/{frontend}/routes/{route}` |     `GET`        | Get a route in a frontend                 | | ||||
|  | ||||
| <1> See [Rest](/configuration/backends/rest/#api) for more information. | ||||
|  | ||||
| !!! warning | ||||
|     For compatibility reason, when you activate the rest provider, you can use `web` or `rest` as `provider` value. | ||||
|     But be careful, in the configuration for all providers the key is still `web`. | ||||
|  | ||||
| ### Address / Port | ||||
|  | ||||
| You can define a custom address/port like this: | ||||
|  | ||||
| ```toml | ||||
| defaultEntryPoints = ["http"] | ||||
|  | ||||
| [entryPoints] | ||||
|   [entryPoints.http] | ||||
|   address = ":80" | ||||
|  | ||||
|   [entryPoints.foo] | ||||
|   address = ":8082" | ||||
|  | ||||
|   [entryPoints.bar] | ||||
|   address = ":8083" | ||||
|  | ||||
| [ping] | ||||
| entryPoint = "foo" | ||||
|  | ||||
| [api] | ||||
| entryPoint = "bar" | ||||
| ``` | ||||
|  | ||||
| In the above example, you would access a regular path, administration panel, and health-check as follows: | ||||
|  | ||||
| * Regular path: `http://hostname:80/path` | ||||
| * Admin Panel: `http://hostname:8083/` | ||||
| * Ping URL: `http://hostname:8082/ping` | ||||
|  | ||||
| In the above example, it is _very_ important to create a named dedicated entry point, and do **not** include it in `defaultEntryPoints`. | ||||
| Otherwise, you are likely to expose _all_ services via that entry point. | ||||
|  | ||||
| ### Custom Path | ||||
|  | ||||
| You can define a custom path like this: | ||||
|  | ||||
| ```toml | ||||
| defaultEntryPoints = ["http"] | ||||
|  | ||||
| [entryPoints] | ||||
|   [entryPoints.http] | ||||
|   address = ":80" | ||||
|  | ||||
|   [entryPoints.foo] | ||||
|   address = ":8080" | ||||
|  | ||||
|   [entryPoints.bar] | ||||
|   address = ":8081" | ||||
|  | ||||
| # Activate API and Dashboard | ||||
| [api] | ||||
| entryPoint = "bar" | ||||
| dashboard = true | ||||
|  | ||||
| [file] | ||||
|   [backends] | ||||
|     [backends.backend1] | ||||
|       [backends.backend1.servers.server1] | ||||
|       url = "http://127.0.0.1:8081" | ||||
|  | ||||
|   [frontends] | ||||
|     [frontends.frontend1] | ||||
|     entryPoints = ["foo"] | ||||
|     backend = "backend1" | ||||
|       [frontends.frontend1.routes.test_1] | ||||
|       rule = "PathPrefixStrip:/yourprefix;PathPrefix:/yourprefix" | ||||
| ``` | ||||
|  | ||||
| ### Authentication | ||||
|  | ||||
| You can define the authentication like this: | ||||
|  | ||||
| ```toml | ||||
| defaultEntryPoints = ["http"] | ||||
|  | ||||
| [entryPoints] | ||||
|   [entryPoints.http] | ||||
|   address = ":80" | ||||
|  | ||||
|  [entryPoints.foo] | ||||
|    address=":8080" | ||||
|    [entryPoints.foo.auth] | ||||
|      [entryPoints.foo.auth.basic] | ||||
|        users = [ | ||||
|          "test:$apr1$H6uskkkW$IgXLP6ewTrSuBkTrqE8wj/", | ||||
|          "test2:$apr1$d9hr9HBB$4HxwgUir3HP4EsggP/QNo0", | ||||
|        ] | ||||
|  | ||||
| [api] | ||||
| entrypoint="foo" | ||||
| ``` | ||||
|  | ||||
| For more information, see [entry points](/configuration/entrypoints/) . | ||||
|  | ||||
| ### Provider call example | ||||
|  | ||||
| ```shell | ||||
| curl -s "http://localhost:8080/api" | jq . | ||||
| ``` | ||||
| ```json | ||||
| { | ||||
|   "file": { | ||||
|     "frontends": { | ||||
|       "frontend2": { | ||||
|         "routes": { | ||||
|           "test_2": { | ||||
|             "rule": "Path:/test" | ||||
|           } | ||||
|         }, | ||||
|         "backend": "backend1" | ||||
|       }, | ||||
|       "frontend1": { | ||||
|         "routes": { | ||||
|           "test_1": { | ||||
|             "rule": "Host:test.localhost" | ||||
|           } | ||||
|         }, | ||||
|         "backend": "backend2" | ||||
|       } | ||||
|     }, | ||||
|     "backends": { | ||||
|       "backend2": { | ||||
|         "loadBalancer": { | ||||
|           "method": "drr" | ||||
|         }, | ||||
|         "servers": { | ||||
|           "server2": { | ||||
|             "weight": 2, | ||||
|             "URL": "http://172.17.0.5:80" | ||||
|           }, | ||||
|           "server1": { | ||||
|             "weight": 1, | ||||
|             "url": "http://172.17.0.4:80" | ||||
|           } | ||||
|         } | ||||
|       }, | ||||
|       "backend1": { | ||||
|         "loadBalancer": { | ||||
|           "method": "wrr" | ||||
|         }, | ||||
|         "circuitBreaker": { | ||||
|           "expression": "NetworkErrorRatio() > 0.5" | ||||
|         }, | ||||
|         "servers": { | ||||
|           "server2": { | ||||
|             "weight": 1, | ||||
|             "url": "http://172.17.0.3:80" | ||||
|           }, | ||||
|           "server1": { | ||||
|             "weight": 10, | ||||
|             "url": "http://172.17.0.2:80" | ||||
|           } | ||||
|         } | ||||
|       } | ||||
|     } | ||||
|   } | ||||
| } | ||||
| ``` | ||||
|  | ||||
| ### Cluster Leadership | ||||
|  | ||||
| ```shell | ||||
| curl -s "http://localhost:8080/cluster/leader" | jq . | ||||
| ``` | ||||
| ```shell | ||||
| < HTTP/1.1 200 OK | ||||
| < Content-Type: application/json; charset=UTF-8 | ||||
| < Date: xxx | ||||
| < Content-Length: 15 | ||||
| ``` | ||||
| If the given node is not a cluster leader, an HTTP status of `429-Too-Many-Requests` will be returned. | ||||
| ```json | ||||
| { | ||||
|   // current leadership status of the queried node | ||||
|   "leader": true | ||||
| } | ||||
| ``` | ||||
|  | ||||
| ### Health | ||||
|  | ||||
| ```shell | ||||
| curl -s "http://localhost:8080/health" | jq . | ||||
| ``` | ||||
| ```json | ||||
| { | ||||
|   // Træfik PID | ||||
|   "pid": 2458, | ||||
|   // Træfik server uptime (formated time) | ||||
|   "uptime": "39m6.885931127s", | ||||
|   //  Træfik server uptime in seconds | ||||
|   "uptime_sec": 2346.885931127, | ||||
|   // current server date | ||||
|   "time": "2015-10-07 18:32:24.362238909 +0200 CEST", | ||||
|   // current server date in seconds | ||||
|   "unixtime": 1444235544, | ||||
|   // count HTTP response status code in realtime | ||||
|   "status_code_count": { | ||||
|     "502": 1 | ||||
|   }, | ||||
|   // count HTTP response status code since Træfik started | ||||
|   "total_status_code_count": { | ||||
|     "200": 7, | ||||
|     "404": 21, | ||||
|     "502": 13 | ||||
|   }, | ||||
|   // count HTTP response | ||||
|   "count": 1, | ||||
|   // count HTTP response | ||||
|   "total_count": 41, | ||||
|   // sum of all response time (formated time) | ||||
|   "total_response_time": "35.456865605s", | ||||
|   // sum of all response time in seconds | ||||
|   "total_response_time_sec": 35.456865605, | ||||
|   // average response time (formated time) | ||||
|   "average_response_time": "864.8016ms", | ||||
|   // average response time in seconds | ||||
|   "average_response_time_sec": 0.8648016000000001, | ||||
|  | ||||
|   // request statistics [requires --statistics to be set] | ||||
|   // ten most recent requests with 4xx and 5xx status codes | ||||
|   "recent_errors": [ | ||||
|     { | ||||
|       // status code | ||||
|       "status_code": 500, | ||||
|       // description of status code | ||||
|       "status": "Internal Server Error", | ||||
|       // request HTTP method | ||||
|       "method": "GET", | ||||
|       // request hostname | ||||
|       "host": "localhost", | ||||
|       // request path | ||||
|       "path": "/path", | ||||
|       // RFC 3339 formatted date/time | ||||
|       "time": "2016-10-21T16:59:15.418495872-07:00" | ||||
|     } | ||||
|   ] | ||||
| } | ||||
| ``` | ||||
|  | ||||
| ## Metrics | ||||
|  | ||||
| You can enable Traefik to export internal metrics to different monitoring systems. | ||||
|  | ||||
| ```toml | ||||
| [api] | ||||
|   # ... | ||||
|  | ||||
|   # Enable more detailed statistics. | ||||
|   [api.statistics] | ||||
|  | ||||
|     # Number of recent errors logged. | ||||
|     # | ||||
|     # Default: 10 | ||||
|     # | ||||
|     recentErrors = 10 | ||||
|  | ||||
|   # ... | ||||
| ``` | ||||
|  | ||||
| | Path       | Method        | Description             | | ||||
| |------------|---------------|-------------------------| | ||||
| | `/metrics` |     `GET`     | Export internal metrics | | ||||
| @@ -1,59 +0,0 @@ | ||||
| # BoltDB Backend | ||||
|  | ||||
| Træfik can be configured to use BoltDB as a backend configuration. | ||||
|  | ||||
| ```toml | ||||
| ################################################################ | ||||
| # BoltDB configuration backend | ||||
| ################################################################ | ||||
|  | ||||
| # Enable BoltDB configuration backend. | ||||
| [boltdb] | ||||
|  | ||||
| # BoltDB file. | ||||
| # | ||||
| # Required | ||||
| # Default: "127.0.0.1:4001" | ||||
| # | ||||
| endpoint = "/my.db" | ||||
|  | ||||
| # Enable watch BoltDB changes. | ||||
| # | ||||
| # Optional | ||||
| # Default: true | ||||
| # | ||||
| watch = true | ||||
|  | ||||
| # Prefix used for KV store. | ||||
| # | ||||
| # Optional | ||||
| # Default: "/traefik" | ||||
| # | ||||
| prefix = "/traefik" | ||||
|  | ||||
| # Override default configuration template. | ||||
| # For advanced users :) | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| filename = "boltdb.tmpl" | ||||
|  | ||||
| # Use BoltDB user/pass authentication. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| # username = foo | ||||
| # password = bar | ||||
|  | ||||
| # Enable BoltDB TLS connection. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| #    [boltdb.tls] | ||||
| #    ca = "/etc/ssl/ca.crt" | ||||
| #    cert = "/etc/ssl/boltdb.crt" | ||||
| #    key = "/etc/ssl/boltdb.key" | ||||
| #    insecureskipverify = true | ||||
| ``` | ||||
|  | ||||
| To enable constraints see [backend-specific constraints section](/configuration/commons/#backend-specific). | ||||
| @@ -1,61 +0,0 @@ | ||||
| # Consul Key-Value Backend | ||||
|  | ||||
| Træfik can be configured to use Consul as a backend configuration. | ||||
|  | ||||
| ```toml | ||||
| ################################################################ | ||||
| # Consul KV configuration backend | ||||
| ################################################################ | ||||
|  | ||||
| # Enable Consul KV configuration backend. | ||||
| [consul] | ||||
|  | ||||
| # Consul server endpoint. | ||||
| # | ||||
| # Required | ||||
| # Default: "127.0.0.1:8500" | ||||
| # | ||||
| endpoint = "127.0.0.1:8500" | ||||
|  | ||||
| # Enable watch Consul changes. | ||||
| # | ||||
| # Optional | ||||
| # Default: true | ||||
| # | ||||
| watch = true | ||||
|  | ||||
| # Prefix used for KV store. | ||||
| # | ||||
| # Optional | ||||
| # Default: traefik | ||||
| # | ||||
| prefix = "traefik" | ||||
|  | ||||
| # Override default configuration template. | ||||
| # For advanced users :) | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| # filename = "consul.tmpl" | ||||
|  | ||||
| # Use Consul user/pass authentication. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| # username = foo | ||||
| # password = bar | ||||
|  | ||||
| # Enable Consul TLS connection. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| #    [consul.tls] | ||||
| #    ca = "/etc/ssl/ca.crt" | ||||
| #    cert = "/etc/ssl/consul.crt" | ||||
| #    key = "/etc/ssl/consul.key" | ||||
| #    insecureskipverify = true | ||||
| ``` | ||||
|  | ||||
| To enable constraints see [backend-specific constraints section](/configuration/commons/#backend-specific). | ||||
|  | ||||
| Please refer to the [Key Value storage structure](/user-guide/kv-config/#key-value-storage-structure) section to get documentation on Traefik KV structure. | ||||
| @@ -1,168 +0,0 @@ | ||||
| # Consul Catalog backend | ||||
|  | ||||
| Træfik can be configured to use service discovery catalog of Consul as a backend configuration. | ||||
|  | ||||
| ```toml | ||||
| ################################################################ | ||||
| # Consul Catalog configuration backend | ||||
| ################################################################ | ||||
|  | ||||
| # Enable Consul Catalog configuration backend. | ||||
| [consulCatalog] | ||||
|  | ||||
| # Consul server endpoint. | ||||
| # | ||||
| # Required | ||||
| # Default: "127.0.0.1:8500" | ||||
| # | ||||
| endpoint = "127.0.0.1:8500" | ||||
|  | ||||
| # Expose Consul catalog services by default in Traefik. | ||||
| # | ||||
| # Optional | ||||
| # Default: true | ||||
| # | ||||
| exposedByDefault = false | ||||
|  | ||||
| # Default domain used. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| domain = "consul.localhost" | ||||
|  | ||||
| # Prefix for Consul catalog tags. | ||||
| # | ||||
| # Optional | ||||
| # Default: "traefik" | ||||
| # | ||||
| prefix = "traefik" | ||||
|  | ||||
| # Default frontEnd Rule for Consul services. | ||||
| # | ||||
| # The format is a Go Template with: | ||||
| # - ".ServiceName", ".Domain" and ".Attributes" available | ||||
| # - "getTag(name, tags, defaultValue)", "hasTag(name, tags)" and "getAttribute(name, tags, defaultValue)" functions are available | ||||
| # - "getAttribute(...)" function uses prefixed tag names based on "prefix" value | ||||
| # | ||||
| # Optional | ||||
| # Default: "Host:{{.ServiceName}}.{{.Domain}}" | ||||
| # | ||||
| #frontEndRule = "Host:{{.ServiceName}}.{{.Domain}}" | ||||
|  | ||||
| # Enable Consul catalog TLS connection. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| #    [consulCatalog.tls] | ||||
| #    ca = "/etc/ssl/ca.crt" | ||||
| #    cert = "/etc/ssl/consul.crt" | ||||
| #    key = "/etc/ssl/consul.key" | ||||
| #    insecureskipverify = true | ||||
| ``` | ||||
|  | ||||
| This backend will create routes matching on hostname based on the service name used in Consul. | ||||
|  | ||||
| To enable constraints see [backend-specific constraints section](/configuration/commons/#backend-specific). | ||||
|  | ||||
| ## Tags | ||||
|  | ||||
| Additional settings can be defined using Consul Catalog tags. | ||||
|  | ||||
| !!! note | ||||
|     The default prefix is `traefik`. | ||||
|  | ||||
| | Label                                                       | Description                                                                                                                                                                                                            | | ||||
| |-------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | ||||
| | `<prefix>.enable=false`                                     | Disable this container in Træfik.                                                                                                                                                                                      | | ||||
| | `<prefix>.port=80`                                          | Register this port. Useful when the container exposes multiples ports.                                                                                                                                                 | | ||||
| | `<prefix>.protocol=https`                                   | Override the default `http` protocol.                                                                                                                                                                                  | | ||||
| | `<prefix>.weight=10`                                        | Assign this weight to the container.                                                                                                                                                                                   | | ||||
| | `traefik.backend.buffering.maxRequestBodyBytes=0`           | See [buffering](/configuration/commons/#buffering) section.                                                                                                                                                            | | ||||
| | `traefik.backend.buffering.maxResponseBodyBytes=0`          | See [buffering](/configuration/commons/#buffering) section.                                                                                                                                                            | | ||||
| | `traefik.backend.buffering.memRequestBodyBytes=0`           | See [buffering](/configuration/commons/#buffering) section.                                                                                                                                                            | | ||||
| | `traefik.backend.buffering.memResponseBodyBytes=0`          | See [buffering](/configuration/commons/#buffering) section.                                                                                                                                                            | | ||||
| | `traefik.backend.buffering.retryExpression=EXPR`            | See [buffering](/configuration/commons/#buffering) section.                                                                                                                                                            | | ||||
| | `<prefix>.backend.circuitbreaker.expression=EXPR`           | Create a [circuit breaker](/basics/#backends) to be used against the backend. ex: `NetworkErrorRatio() > 0.`                                                                                                           | | ||||
| | `<prefix>.backend.healthcheck.path=/health`                 | Enable health check for the backend, hitting the container at `path`.                                                                                                                                                  | | ||||
| | `<prefix>.backend.healthcheck.port=8080`                    | Allow to use a different port for the health check.                                                                                                                                                                    | | ||||
| | `<prefix>.backend.healthcheck.interval=1s`                  | Define the health check interval.                                                                                                                                                                                      | | ||||
| | `<prefix>.backend.loadbalancer.method=drr`                  | Override the default `wrr` load balancer algorithm.                                                                                                                                                                    | | ||||
| | `<prefix>.backend.loadbalancer.stickiness=true`             | Enable backend sticky sessions.                                                                                                                                                                                        | | ||||
| | `<prefix>.backend.loadbalancer.stickiness.cookieName=NAME`  | Manually set the cookie name for sticky sessions.                                                                                                                                                                      | | ||||
| | `<prefix>.backend.loadbalancer.sticky=true`                 | Enable backend sticky sessions. (DEPRECATED)                                                                                                                                                                           | | ||||
| | `<prefix>.backend.maxconn.amount=10`                        | Set a maximum number of connections to the backend.<br>Must be used in conjunction with the below label to take effect.                                                                                                | | ||||
| | `<prefix>.backend.maxconn.extractorfunc=client.ip`          | Set the function to be used against the request to determine what to limit maximum connections to the backend by.<br>Must be used in conjunction with the above label to take effect.                                  | | ||||
| | `<prefix>.frontend.auth.basic=EXPR`                         | Sets basic authentication for that frontend in CSV format: `User:Hash,User:Hash`                                                                                                                                       | | ||||
| | `<prefix>.frontend.entryPoints=http,https`                  | Assign this frontend to entry points `http` and `https`.<br>Overrides `defaultEntryPoints`                                                                                                                             | | ||||
| | `<prefix>.frontend.errors.<name>.backend=NAME`              | See [custom error pages](/configuration/commons/#custom-error-pages) section.                                                                                                                                          | | ||||
| | `<prefix>.frontend.errors.<name>.query=PATH`                | See [custom error pages](/configuration/commons/#custom-error-pages) section.                                                                                                                                          | | ||||
| | `<prefix>.frontend.errors.<name>.status=RANGE`              | See [custom error pages](/configuration/commons/#custom-error-pages) section.                                                                                                                                          | | ||||
| | `<prefix>.frontend.passHostHeader=true`                     | Forward client `Host` header to the backend.                                                                                                                                                                           | | ||||
| | `<prefix>.frontend.passTLSCert=true`                        | Forward TLS Client certificates to the backend.                                                                                                                                                                        | | ||||
| | `<prefix>.frontend.priority=10`                             | Override default frontend priority.                                                                                                                                                                                    | | ||||
| | `<prefix>.frontend.rateLimit.extractorFunc=EXP`             | See [rate limiting](/configuration/commons/#rate-limiting) section.                                                                                                                                                    | | ||||
| | `<prefix>.frontend.rateLimit.rateSet.<name>.period=6`       | See [rate limiting](/configuration/commons/#rate-limiting) section.                                                                                                                                                    | | ||||
| | `<prefix>.frontend.rateLimit.rateSet.<name>.average=6`      | See [rate limiting](/configuration/commons/#rate-limiting) section.                                                                                                                                                    | | ||||
| | `<prefix>.frontend.rateLimit.rateSet.<name>.burst=6`        | See [rate limiting](/configuration/commons/#rate-limiting) section.                                                                                                                                                    | | ||||
| | `<prefix>.frontend.redirect.entryPoint=https`               | Enables Redirect to another entryPoint for that frontend (e.g. HTTPS).                                                                                                                                                 | | ||||
| | `<prefix>.frontend.redirect.regex=^http://localhost/(.*)`   | Redirect to another URL for that frontend.<br>Must be set with `traefik.frontend.redirect.replacement`.                                                                                                                | | ||||
| | `<prefix>.frontend.redirect.replacement=http://mydomain/$1` | Redirect to another URL for that frontend.<br>Must be set with `traefik.frontend.redirect.regex`.                                                                                                                      | | ||||
| | `<prefix>.frontend.redirect.permanent=true`                 | Return 301 instead of 302.                                                                                                                                                                                             | | ||||
| | `<prefix>.frontend.rule=EXPR`                               | Override the default frontend rule. Default: `Host:{{.ServiceName}}.{{.Domain}}`.                                                                                                                                      | | ||||
| | `<prefix>.frontend.whiteList.sourceRange=RANGE`             | List of IP-Ranges which are allowed to access.<br>An unset or empty list allows all Source-IPs to access. If one of the Net-Specifications are invalid, the whole list is invalid and allows all Source-IPs to access. | | ||||
| | `<prefix>.frontend.whiteList.useXForwardedFor=true`         | Use `X-Forwarded-For` header as valid source of IP for the white list.                                                                                                                                                 | | ||||
|  | ||||
| ### Custom Headers | ||||
|  | ||||
| !!! note | ||||
|     The default prefix is `traefik`. | ||||
|  | ||||
| | Label                                                  | Description                                                                                                                                                                         | | ||||
| |--------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | ||||
| | `<prefix>.frontend.headers.customRequestHeaders=EXPR ` | Provides the container with custom request headers that will be appended to each request forwarded to the container.<br>Format: <code>HEADER:value||HEADER2:value2</code> | | ||||
| | `<prefix>.frontend.headers.customResponseHeaders=EXPR` | Appends the headers to each response returned by the container, before forwarding the response to the client.<br>Format: <code>HEADER:value||HEADER2:value2</code>        | | ||||
|  | ||||
| ### Security Headers | ||||
|  | ||||
| !!! note | ||||
|     The default prefix is `traefik`. | ||||
|  | ||||
| | Label                                                     | Description                                                                                                                                                                                         | | ||||
| |-----------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | ||||
| | `<prefix>.frontend.headers.allowedHosts=EXPR`             | Provides a list of allowed hosts that requests will be processed.<br>Format: `Host1,Host2`                                                                                                          | | ||||
| | `<prefix>.frontend.headers.hostsProxyHeaders=EXPR`        | Provides a list of headers that the proxied hostname may be stored.<br>Format: `HEADER1,HEADER2`                                                                                                    | | ||||
| | `<prefix>.frontend.headers.SSLRedirect=true`              | Forces the frontend to redirect to SSL if a non-SSL request is sent.                                                                                                                                | | ||||
| | `<prefix>.frontend.headers.SSLTemporaryRedirect=true`     | Forces the frontend to redirect to SSL if a non-SSL request is sent, but by sending a 302 instead of a 301.                                                                                         | | ||||
| | `<prefix>.frontend.headers.SSLHost=HOST`                  | This setting configures the hostname that redirects will be based on. Default is "", which is the same host as the request.                                                                         | | ||||
| | `<prefix>.frontend.headers.SSLProxyHeaders=EXPR`          | Header combinations that would signify a proper SSL Request (Such as `X-Forwarded-For:https`).<br>Format:  <code>HEADER:value||HEADER2:value2</code>                                      | | ||||
| | `<prefix>.frontend.headers.STSSeconds=315360000`          | Sets the max-age of the STS header.                                                                                                                                                                 | | ||||
| | `<prefix>.frontend.headers.STSIncludeSubdomains=true`     | Adds the `IncludeSubdomains` section of the STS  header.                                                                                                                                            | | ||||
| | `<prefix>.frontend.headers.STSPreload=true`               | Adds the preload flag to the STS  header.                                                                                                                                                           | | ||||
| | `<prefix>.frontend.headers.forceSTSHeader=false`          | Adds the STS  header to non-SSL requests.                                                                                                                                                           | | ||||
| | `<prefix>.frontend.headers.frameDeny=false`               | Adds the `X-Frame-Options` header with the value of `DENY`.                                                                                                                                         | | ||||
| | `<prefix>.frontend.headers.customFrameOptionsValue=VALUE` | Overrides the `X-Frame-Options` header with the custom value.                                                                                                                                       | | ||||
| | `<prefix>.frontend.headers.contentTypeNosniff=true`       | Adds the `X-Content-Type-Options` header with the value `nosniff`.                                                                                                                                  | | ||||
| | `<prefix>.frontend.headers.browserXSSFilter=true`         | Adds the X-XSS-Protection header with the value `1; mode=block`.                                                                                                                                    | | ||||
| | `<prefix>.frontend.headers.customBrowserXSSValue=VALUE`   | Set custom value for X-XSS-Protection header. This overrides the BrowserXssFilter option.                                                                                                           | | ||||
| | `<prefix>.frontend.headers.contentSecurityPolicy=VALUE`   | Adds CSP Header with the custom value.                                                                                                                                                              | | ||||
| | `<prefix>.frontend.headers.publicKey=VALUE`               | Adds pinned HTST public key header.                                                                                                                                                                 | | ||||
| | `<prefix>.frontend.headers.referrerPolicy=VALUE`          | Adds referrer policy  header.                                                                                                                                                                       | | ||||
| | `<prefix>.frontend.headers.isDevelopment=false`           | This will cause the `AllowedHosts`, `SSLRedirect`, and `STSSeconds`/`STSIncludeSubdomains` options to be ignored during development.<br>When deploying to production, be sure to set this to false. | | ||||
|  | ||||
| ### Examples | ||||
|  | ||||
| If you want that Træfik uses Consul tags correctly you need to defined them like that: | ||||
|  | ||||
| ```js | ||||
| traefik.enable=true | ||||
| traefik.tags=api | ||||
| traefik.tags=external | ||||
| ``` | ||||
|  | ||||
| If the prefix defined in Træfik configuration is `bla`, tags need to be defined like that: | ||||
|  | ||||
| ```js | ||||
| bla.enable=true | ||||
| bla.tags=api | ||||
| bla.tags=external | ||||
| ``` | ||||
| @@ -1,351 +0,0 @@ | ||||
|  | ||||
| # Docker Backend | ||||
|  | ||||
| Træfik can be configured to use Docker as a backend configuration. | ||||
|  | ||||
| ## Docker | ||||
|  | ||||
| ```toml | ||||
| ################################################################ | ||||
| # Docker configuration backend | ||||
| ################################################################ | ||||
|  | ||||
| # Enable Docker configuration backend. | ||||
| [docker] | ||||
|  | ||||
| # Docker server endpoint. Can be a tcp or a unix socket endpoint. | ||||
| # | ||||
| # Required | ||||
| # | ||||
| endpoint = "unix:///var/run/docker.sock" | ||||
|  | ||||
| # Default domain used. | ||||
| # Can be overridden by setting the "traefik.domain" label on a container. | ||||
| # | ||||
| # Required | ||||
| # | ||||
| domain = "docker.localhost" | ||||
|  | ||||
| # Enable watch docker changes. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| watch = true | ||||
|  | ||||
| # Override default configuration template. | ||||
| # For advanced users :) | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| # filename = "docker.tmpl" | ||||
|  | ||||
| # Override template version | ||||
| # For advanced users :) | ||||
| # | ||||
| # Optional | ||||
| # - "1": previous template version (must be used only with older custom templates, see "filename") | ||||
| # - "2": current template version (must be used to force template version when "filename" is used) | ||||
| # | ||||
| # templateVersion = "2" | ||||
|  | ||||
| # Expose containers by default in Traefik. | ||||
| # If set to false, containers that don't have `traefik.enable=true` will be ignored. | ||||
| # | ||||
| # Optional | ||||
| # Default: true | ||||
| # | ||||
| exposedbydefault = true | ||||
|  | ||||
| # Use the IP address from the binded port instead of the inner network one. | ||||
| # For specific use-case :) | ||||
| # | ||||
| # Optional | ||||
| # Default: false | ||||
| # | ||||
| usebindportip = true | ||||
|  | ||||
| # Use Swarm Mode services as data provider. | ||||
| # | ||||
| # Optional | ||||
| # Default: false | ||||
| # | ||||
| swarmmode = false | ||||
|  | ||||
| # Enable docker TLS connection. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| #  [docker.tls] | ||||
| #  ca = "/etc/ssl/ca.crt" | ||||
| #  cert = "/etc/ssl/docker.crt" | ||||
| #  key = "/etc/ssl/docker.key" | ||||
| #  insecureskipverify = true | ||||
| ``` | ||||
|  | ||||
| To enable constraints see [backend-specific constraints section](/configuration/commons/#backend-specific). | ||||
|  | ||||
|  | ||||
| ## Docker Swarm Mode | ||||
|  | ||||
| ```toml | ||||
| ################################################################ | ||||
| # Docker Swarmmode configuration backend | ||||
| ################################################################ | ||||
|  | ||||
| # Enable Docker configuration backend. | ||||
| [docker] | ||||
|  | ||||
| # Docker server endpoint. | ||||
| # Can be a tcp or a unix socket endpoint. | ||||
| # | ||||
| # Required | ||||
| # Default: "unix:///var/run/docker.sock" | ||||
| # | ||||
| endpoint = "tcp://127.0.0.1:2375" | ||||
|  | ||||
| # Default domain used. | ||||
| # Can be overridden by setting the "traefik.domain" label on a services. | ||||
| # | ||||
| # Optional | ||||
| # Default: "" | ||||
| # | ||||
| domain = "docker.localhost" | ||||
|  | ||||
| # Enable watch docker changes. | ||||
| # | ||||
| # Optional | ||||
| # Default: true | ||||
| # | ||||
| watch = true | ||||
|  | ||||
| # Use Docker Swarm Mode as data provider. | ||||
| # | ||||
| # Optional | ||||
| # Default: false | ||||
| # | ||||
| swarmmode = true | ||||
|  | ||||
| # Override default configuration template. | ||||
| # For advanced users :) | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| # filename = "docker.tmpl" | ||||
|  | ||||
| # Override template version | ||||
| # For advanced users :) | ||||
| # | ||||
| # Optional | ||||
| # - "1": previous template version (must be used only with older custom templates, see "filename") | ||||
| # - "2": current template version (must be used to force template version when "filename" is used) | ||||
| # | ||||
| # templateVersion = "2" | ||||
|  | ||||
| # Expose services by default in Traefik. | ||||
| # | ||||
| # Optional | ||||
| # Default: true | ||||
| # | ||||
| exposedbydefault = false | ||||
|  | ||||
| # Enable docker TLS connection. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| #  [docker.tls] | ||||
| #  ca = "/etc/ssl/ca.crt" | ||||
| #  cert = "/etc/ssl/docker.crt" | ||||
| #  key = "/etc/ssl/docker.key" | ||||
| #  insecureskipverify = true | ||||
| ``` | ||||
|  | ||||
| To enable constraints see [backend-specific constraints section](/configuration/commons/#backend-specific). | ||||
|  | ||||
| ## Labels: overriding default behavior | ||||
|  | ||||
| ### Using Docker with Swarm Mode | ||||
|  | ||||
| If you use a compose file with the Swarm mode, labels should be defined in the `deploy` part of your service. | ||||
| This behavior is only enabled for docker-compose version 3+ ([Compose file reference](https://docs.docker.com/compose/compose-file/#labels-1)). | ||||
|  | ||||
| ```yaml | ||||
| version: "3" | ||||
| services: | ||||
|   whoami: | ||||
|     deploy: | ||||
|       labels: | ||||
|         traefik.docker.network: traefik | ||||
| ``` | ||||
|  | ||||
| ### Using Docker Compose | ||||
|  | ||||
| If you are intending to use only Docker Compose commands (e.g. `docker-compose up --scale whoami=2 -d`), labels should be under your service, otherwise they will be ignored. | ||||
|  | ||||
| ```yaml | ||||
| version: "3" | ||||
| services: | ||||
|   whoami: | ||||
|     labels: | ||||
|       traefik.docker.network: traefik | ||||
| ``` | ||||
|  | ||||
| ### On Containers | ||||
|  | ||||
| Labels can be used on containers to override default behavior. | ||||
|  | ||||
| | Label                                                      | Description                                                                                                                                                                                                               | | ||||
| |------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | ||||
| | `traefik.docker.network`                                   | Set the docker network to use for connections to this container. [1]                                                                                                                                                      | | ||||
| | `traefik.enable=false`                                     | Disable this container in Træfik                                                                                                                                                                                          | | ||||
| | `traefik.port=80`                                          | Register this port. Useful when the container exposes multiples ports.                                                                                                                                                    | | ||||
| | `traefik.protocol=https`                                   | Override the default `http` protocol                                                                                                                                                                                      | | ||||
| | `traefik.weight=10`                                        | Assign this weight to the container                                                                                                                                                                                       | | ||||
| | `traefik.backend=foo`                                      | Give the name `foo` to the generated backend for this container.                                                                                                                                                          | | ||||
| | `traefik.backend.buffering.maxRequestBodyBytes=0`          | See [buffering](/configuration/commons/#buffering) section.                                                                                                                                                               | | ||||
| | `traefik.backend.buffering.maxResponseBodyBytes=0`         | See [buffering](/configuration/commons/#buffering) section.                                                                                                                                                               | | ||||
| | `traefik.backend.buffering.memRequestBodyBytes=0`          | See [buffering](/configuration/commons/#buffering) section.                                                                                                                                                               | | ||||
| | `traefik.backend.buffering.memResponseBodyBytes=0`         | See [buffering](/configuration/commons/#buffering) section.                                                                                                                                                               | | ||||
| | `traefik.backend.buffering.retryExpression=EXPR`           | See [buffering](/configuration/commons/#buffering) section.                                                                                                                                                               | | ||||
| | `traefik.backend.circuitbreaker.expression=EXPR`           | Create a [circuit breaker](/basics/#backends) to be used against the backend                                                                                                                                              | | ||||
| | `traefik.backend.healthcheck.path=/health`                 | Enable health check for the backend, hitting the container at `path`.                                                                                                                                                     | | ||||
| | `traefik.backend.healthcheck.port=8080`                    | Allow to use a different port for the health check.                                                                                                                                                                       | | ||||
| | `traefik.backend.healthcheck.interval=1s`                  | Define the health check interval.                                                                                                                                                                                         | | ||||
| | `traefik.backend.loadbalancer.method=drr`                  | Override the default `wrr` load balancer algorithm                                                                                                                                                                        | | ||||
| | `traefik.backend.loadbalancer.stickiness=true`             | Enable backend sticky sessions                                                                                                                                                                                            | | ||||
| | `traefik.backend.loadbalancer.stickiness.cookieName=NAME`  | Manually set the cookie name for sticky sessions                                                                                                                                                                          | | ||||
| | `traefik.backend.loadbalancer.sticky=true`                 | Enable backend sticky sessions (DEPRECATED)                                                                                                                                                                               | | ||||
| | `traefik.backend.loadbalancer.swarm=true`                  | Use Swarm's inbuilt load balancer (only relevant under Swarm Mode).                                                                                                                                                       | | ||||
| | `traefik.backend.maxconn.amount=10`                        | Set a maximum number of connections to the backend.<br>Must be used in conjunction with the below label to take effect.                                                                                                   | | ||||
| | `traefik.backend.maxconn.extractorfunc=client.ip`          | Set the function to be used against the request to determine what to limit maximum connections to the backend by.<br>Must be used in conjunction with the above label to take effect.                                     | | ||||
| | `traefik.frontend.auth.basic=EXPR`                         | Sets basic authentication for that frontend in CSV format: `User:Hash,User:Hash`                                                                                                                                          | | ||||
| | `traefik.frontend.entryPoints=http,https`                  | Assign this frontend to entry points `http` and `https`.<br>Overrides `defaultEntryPoints`                                                                                                                                | | ||||
| | `traefik.frontend.errors.<name>.backend=NAME`              | See [custom error pages](/configuration/commons/#custom-error-pages) section.                                                                                                                                             | | ||||
| | `traefik.frontend.errors.<name>.query=PATH`                | See [custom error pages](/configuration/commons/#custom-error-pages) section.                                                                                                                                             | | ||||
| | `traefik.frontend.errors.<name>.status=RANGE`              | See [custom error pages](/configuration/commons/#custom-error-pages) section.                                                                                                                                             | | ||||
| | `traefik.frontend.passHostHeader=true`                     | Forward client `Host` header to the backend.                                                                                                                                                                              | | ||||
| | `traefik.frontend.passTLSCert=true`                        | Forward TLS Client certificates to the backend.                                                                                                                                                                           | | ||||
| | `traefik.frontend.priority=10`                             | Override default frontend priority                                                                                                                                                                                        | | ||||
| | `traefik.frontend.rateLimit.extractorFunc=EXP`             | See [rate limiting](/configuration/commons/#rate-limiting) section.                                                                                                                                                       | | ||||
| | `traefik.frontend.rateLimit.rateSet.<name>.period=6`       | See [rate limiting](/configuration/commons/#rate-limiting) section.                                                                                                                                                       | | ||||
| | `traefik.frontend.rateLimit.rateSet.<name>.average=6`      | See [rate limiting](/configuration/commons/#rate-limiting) section.                                                                                                                                                       | | ||||
| | `traefik.frontend.rateLimit.rateSet.<name>.burst=6`        | See [rate limiting](/configuration/commons/#rate-limiting) section.                                                                                                                                                       | | ||||
| | `traefik.frontend.redirect.entryPoint=https`               | Enables Redirect to another entryPoint for that frontend (e.g. HTTPS)                                                                                                                                                     | | ||||
| | `traefik.frontend.redirect.regex=^http://localhost/(.*)`   | Redirect to another URL for that frontend.<br>Must be set with `traefik.frontend.redirect.replacement`.                                                                                                                   | | ||||
| | `traefik.frontend.redirect.replacement=http://mydomain/$1` | Redirect to another URL for that frontend.<br>Must be set with `traefik.frontend.redirect.regex`.                                                                                                                         | | ||||
| | `traefik.frontend.redirect.permanent=true`                 | Return 301 instead of 302.                                                                                                                                                                                                | | ||||
| | `traefik.frontend.rule=EXPR`                               | Override the default frontend rule. Default: `Host:{containerName}.{domain}` or `Host:{service}.{project_name}.{domain}` if you are using `docker-compose`.                                                               | | ||||
| | `traefik.frontend.whiteList.sourceRange=RANGE`             | List of IP-Ranges which are allowed to access.<br>An unset or empty list allows all Source-IPs to access.<br>If one of the Net-Specifications are invalid, the whole list is invalid and allows all Source-IPs to access. | | ||||
| | `traefik.frontend.whiteList.useXForwardedFor=true`         | Use `X-Forwarded-For` header as valid source of IP for the white list.                                                                                                                                                    | | ||||
|  | ||||
| [1] `traefik.docker.network`: | ||||
| If a container is linked to several networks, be sure to set the proper network name (you can check with `docker inspect <container_id>`) otherwise it will randomly pick one (depending on how docker is returning them). | ||||
| For instance when deploying docker `stack` from compose files, the compose defined networks will be prefixed with the `stack` name. | ||||
| Or if your service references external network use it's name instead. | ||||
|  | ||||
| #### Custom Headers | ||||
|  | ||||
| | Label                                                 | Description                                                                                                                                                                         | | ||||
| |-------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | ||||
| | `traefik.frontend.headers.customRequestHeaders=EXPR ` | Provides the container with custom request headers that will be appended to each request forwarded to the container.<br>Format: <code>HEADER:value||HEADER2:value2</code> | | ||||
| | `traefik.frontend.headers.customResponseHeaders=EXPR` | Appends the headers to each response returned by the container, before forwarding the response to the client.<br>Format: <code>HEADER:value||HEADER2:value2</code>        | | ||||
|  | ||||
| #### Security Headers | ||||
|  | ||||
| | Label                                                    | Description                                                                                                                                                                                         | | ||||
| |----------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | ||||
| | `traefik.frontend.headers.allowedHosts=EXPR`             | Provides a list of allowed hosts that requests will be processed.<br>Format: `Host1,Host2`                                                                                                          | | ||||
| | `traefik.frontend.headers.hostsProxyHeaders=EXPR `       | Provides a list of headers that the proxied hostname may be stored.<br>Format: `HEADER1,HEADER2`                                                                                                    | | ||||
| | `traefik.frontend.headers.SSLRedirect=true`              | Forces the frontend to redirect to SSL if a non-SSL request is sent.                                                                                                                                | | ||||
| | `traefik.frontend.headers.SSLTemporaryRedirect=true`     | Forces the frontend to redirect to SSL if a non-SSL request is sent, but by sending a 302 instead of a 301.                                                                                         | | ||||
| | `traefik.frontend.headers.SSLHost=HOST`                  | This setting configures the hostname that redirects will be based on. Default is "", which is the same host as the request.                                                                         | | ||||
| | `traefik.frontend.headers.SSLProxyHeaders=EXPR`          | Header combinations that would signify a proper SSL Request (Such as `X-Forwarded-For:https`).<br>Format:  <code>HEADER:value||HEADER2:value2</code>                                      | | ||||
| | `traefik.frontend.headers.STSSeconds=315360000`          | Sets the max-age of the STS header.                                                                                                                                                                 | | ||||
| | `traefik.frontend.headers.STSIncludeSubdomains=true`     | Adds the `IncludeSubdomains` section of the STS  header.                                                                                                                                            | | ||||
| | `traefik.frontend.headers.STSPreload=true`               | Adds the preload flag to the STS  header.                                                                                                                                                           | | ||||
| | `traefik.frontend.headers.forceSTSHeader=false`          | Adds the STS  header to non-SSL requests.                                                                                                                                                           | | ||||
| | `traefik.frontend.headers.frameDeny=false`               | Adds the `X-Frame-Options` header with the value of `DENY`.                                                                                                                                         | | ||||
| | `traefik.frontend.headers.customFrameOptionsValue=VALUE` | Overrides the `X-Frame-Options` header with the custom value.                                                                                                                                       | | ||||
| | `traefik.frontend.headers.contentTypeNosniff=true`       | Adds the `X-Content-Type-Options` header with the value `nosniff`.                                                                                                                                  | | ||||
| | `traefik.frontend.headers.browserXSSFilter=true`         | Adds the X-XSS-Protection header with the value `1; mode=block`.                                                                                                                                    | | ||||
| | `traefik.frontend.headers.customBrowserXSSValue=VALUE`   | Set custom value for X-XSS-Protection header. This overrides the BrowserXssFilter option.                                                                                                           | | ||||
| | `traefik.frontend.headers.contentSecurityPolicy=VALUE`   | Adds CSP Header with the custom value.                                                                                                                                                              | | ||||
| | `traefik.frontend.headers.publicKey=VALUE`               | Adds pinned HTST public key header.                                                                                                                                                                 | | ||||
| | `traefik.frontend.headers.referrerPolicy=VALUE`          | Adds referrer policy  header.                                                                                                                                                                       | | ||||
| | `traefik.frontend.headers.isDevelopment=false`           | This will cause the `AllowedHosts`, `SSLRedirect`, and `STSSeconds`/`STSIncludeSubdomains` options to be ignored during development.<br>When deploying to production, be sure to set this to false. | | ||||
|  | ||||
| ### On containers with Multiple Ports (segment labels) | ||||
|  | ||||
| Segment labels are used to define routes to a container exposing multiple ports. | ||||
| A segment is a group of labels that apply to a port exposed by a container. | ||||
| You can define as many segments as ports exposed in a container. | ||||
|  | ||||
| Segment labels override the default behavior. | ||||
|  | ||||
| | Label                                                                     | Description                                                                                      | | ||||
| |---------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------| | ||||
| | `traefik.<segment_name>.port=PORT`                                        | Overrides `traefik.port`. If several ports need to be exposed, the segment labels could be used. | | ||||
| | `traefik.<segment_name>.protocol`                                         | Overrides `traefik.protocol`.                                                                    | | ||||
| | `traefik.<segment_name>.weight`                                           | Assign this segment weight. Overrides `traefik.weight`.                                          | | ||||
| | `traefik.<segment_name>.frontend.auth.basic`                              | Sets a Basic Auth for that frontend                                                              | | ||||
| | `traefik.<segment_name>.frontend.backend=BACKEND`                         | Assign this segment frontend to `BACKEND`. Default is to assign to the segment backend.          | | ||||
| | `traefik.<segment_name>.frontend.entryPoints`                             | Overrides `traefik.frontend.entrypoints`                                                         | | ||||
| | `traefik.<segment_name>.frontend.errors.<name>.backend=NAME`              | See [custom error pages](/configuration/commons/#custom-error-pages) section.                    | | ||||
| | `traefik.<segment_name>.frontend.errors.<name>.query=PATH`                | See [custom error pages](/configuration/commons/#custom-error-pages) section.                    | | ||||
| | `traefik.<segment_name>.frontend.errors.<name>.status=RANGE`              | See [custom error pages](/configuration/commons/#custom-error-pages) section.                    | | ||||
| | `traefik.<segment_name>.frontend.passHostHeader`                          | Overrides `traefik.frontend.passHostHeader`.                                                     | | ||||
| | `traefik.<segment_name>.frontend.passTLSCert`                             | Overrides `traefik.frontend.passTLSCert`.                                                        | | ||||
| | `traefik.<segment_name>.frontend.priority`                                | Overrides `traefik.frontend.priority`.                                                           | | ||||
| | `traefik.<segment_name>.frontend.rateLimit.extractorFunc=EXP`             | See [rate limiting](/configuration/commons/#rate-limiting) section.                              | | ||||
| | `traefik.<segment_name>.frontend.rateLimit.rateSet.<name>.period=6`       | See [rate limiting](/configuration/commons/#rate-limiting) section.                              | | ||||
| | `traefik.<segment_name>.frontend.rateLimit.rateSet.<name>.average=6`      | See [rate limiting](/configuration/commons/#rate-limiting) section.                              | | ||||
| | `traefik.<segment_name>.frontend.rateLimit.rateSet.<name>.burst=6`        | See [rate limiting](/configuration/commons/#rate-limiting) section.                              | | ||||
| | `traefik.<segment_name>.frontend.redirect.entryPoint=https`               | Overrides `traefik.frontend.redirect.entryPoint`.                                                | | ||||
| | `traefik.<segment_name>.frontend.redirect.regex=^http://localhost/(.*)`   | Overrides `traefik.frontend.redirect.regex`.                                                     | | ||||
| | `traefik.<segment_name>.frontend.redirect.replacement=http://mydomain/$1` | Overrides `traefik.frontend.redirect.replacement`.                                               | | ||||
| | `traefik.<segment_name>.frontend.redirect.permanent=true`                 | Return 301 instead of 302.                                                                       | | ||||
| | `traefik.<segment_name>.frontend.rule`                                    | Overrides `traefik.frontend.rule`.                                                               | | ||||
| | `traefik.<segment_name>.frontend.whiteList.sourceRange=RANGE`             | Overrides `traefik.frontend.whiteList.sourceRange`.                                              | | ||||
| | `traefik.<segment_name>.frontend.whiteList.useXForwardedFor=true`         | Overrides `traefik.frontend.whiteList.useXForwardedFor`.                                         | | ||||
|  | ||||
| #### Custom Headers | ||||
|  | ||||
| | Label                                                                | Description                                                                                                                                                                         | | ||||
| |----------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | ||||
| | `traefik.<segment_name>.frontend.headers.customRequestHeaders=EXPR ` | Provides the container with custom request headers that will be appended to each request forwarded to the container.<br>Format: <code>HEADER:value||HEADER2:value2</code> | | ||||
| | `traefik.<segment_name>.frontend.headers.customResponseHeaders=EXPR` | Appends the headers to each response returned by the container, before forwarding the response to the client.<br>Format: <code>HEADER:value||HEADER2:value2</code>        | | ||||
|  | ||||
| #### Security Headers | ||||
|  | ||||
| | Label                                                                   | Description                                                                                                                                                                                         | | ||||
| |-------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | ||||
| | `traefik.<segment_name>.frontend.headers.allowedHosts=EXPR`             | Provides a list of allowed hosts that requests will be processed.<br>Format: `Host1,Host2`                                                                                                          | | ||||
| | `traefik.<segment_name>.frontend.headers.hostsProxyHeaders=EXPR `       | Provides a list of headers that the proxied hostname may be stored.<br>Format: `HEADER1,HEADER2`                                                                                                    | | ||||
| | `traefik.<segment_name>.frontend.headers.SSLRedirect=true`              | Forces the frontend to redirect to SSL if a non-SSL request is sent.                                                                                                                                | | ||||
| | `traefik.<segment_name>.frontend.headers.SSLTemporaryRedirect=true`     | Forces the frontend to redirect to SSL if a non-SSL request is sent, but by sending a 302 instead of a 301.                                                                                         | | ||||
| | `traefik.<segment_name>.frontend.headers.SSLHost=HOST`                  | This setting configures the hostname that redirects will be based on. Default is "", which is the same host as the request.                                                                         | | ||||
| | `traefik.<segment_name>.frontend.headers.SSLProxyHeaders=EXPR`          | Header combinations that would signify a proper SSL Request (Such as `X-Forwarded-For:https`).<br>Format:  <code>HEADER:value||HEADER2:value2</code>                                      | | ||||
| | `traefik.<segment_name>.frontend.headers.STSSeconds=315360000`          | Sets the max-age of the STS header.                                                                                                                                                                 | | ||||
| | `traefik.<segment_name>.frontend.headers.STSIncludeSubdomains=true`     | Adds the `IncludeSubdomains` section of the STS  header.                                                                                                                                            | | ||||
| | `traefik.<segment_name>.frontend.headers.STSPreload=true`               | Adds the preload flag to the STS  header.                                                                                                                                                           | | ||||
| | `traefik.<segment_name>.frontend.headers.forceSTSHeader=false`          | Adds the STS  header to non-SSL requests.                                                                                                                                                           | | ||||
| | `traefik.<segment_name>.frontend.headers.frameDeny=false`               | Adds the `X-Frame-Options` header with the value of `DENY`.                                                                                                                                         | | ||||
| | `traefik.<segment_name>.frontend.headers.customFrameOptionsValue=VALUE` | Overrides the `X-Frame-Options` header with the custom value.                                                                                                                                       | | ||||
| | `traefik.<segment_name>.frontend.headers.contentTypeNosniff=true`       | Adds the `X-Content-Type-Options` header with the value `nosniff`.                                                                                                                                  | | ||||
| | `traefik.<segment_name>.frontend.headers.browserXSSFilter=true`         | Adds the X-XSS-Protection header with the value `1; mode=block`.                                                                                                                                    | | ||||
| | `traefik.<segment_name>.frontend.headers.customBrowserXSSValue=VALUE`   | Set custom value for X-XSS-Protection header. This overrides the BrowserXssFilter option.                                                                                                           | | ||||
| | `traefik.<segment_name>.frontend.headers.contentSecurityPolicy=VALUE`   | Adds CSP Header with the custom value.                                                                                                                                                              | | ||||
| | `traefik.<segment_name>.frontend.headers.publicKey=VALUE`               | Adds pinned HTST public key header.                                                                                                                                                                 | | ||||
| | `traefik.<segment_name>.frontend.headers.referrerPolicy=VALUE`          | Adds referrer policy  header.                                                                                                                                                                       | | ||||
| | `traefik.<segment_name>.frontend.headers.isDevelopment=false`           | This will cause the `AllowedHosts`, `SSLRedirect`, and `STSSeconds`/`STSIncludeSubdomains` options to be ignored during development.<br>When deploying to production, be sure to set this to false. | | ||||
|  | ||||
| !!! note | ||||
|     If a label is defined both as a `container label` and a `segment label` (for example `traefik.<segment_name>.port=PORT` and `traefik.port=PORT` ), the `segment label` is used to defined the `<segment_name>` property (`port` in the example). | ||||
|  | ||||
|     It's possible to mix `container labels` and `segment labels`, in this case `container labels` are used as default value for missing `segment labels` but no frontends are going to be created with the `container labels`. | ||||
|  | ||||
|     More details in this [example](/user-guide/docker-and-lets-encrypt/#labels). | ||||
|  | ||||
| !!! warning | ||||
|     When running inside a container, Træfik will need network access through: | ||||
|  | ||||
|     `docker network connect <network> <traefik-container>` | ||||
| @@ -1,71 +0,0 @@ | ||||
| # DynamoDB Backend | ||||
|  | ||||
| Træfik can be configured to use Amazon DynamoDB as a backend configuration. | ||||
|  | ||||
| ## Configuration | ||||
|  | ||||
| ```toml | ||||
| ################################################################ | ||||
| # DynamoDB configuration backend | ||||
| ################################################################ | ||||
|  | ||||
| # Enable DynamoDB configuration backend. | ||||
| [dynamodb] | ||||
|  | ||||
| # Region to use when connecting to AWS. | ||||
| # | ||||
| # Required | ||||
| # | ||||
| region = "us-west-1" | ||||
|  | ||||
| # DyanmoDB Table Name. | ||||
| # | ||||
| # Optional | ||||
| # Default: "traefik" | ||||
| # | ||||
| tableName = "traefik" | ||||
|  | ||||
| # Enable watch DynamoDB changes. | ||||
| # | ||||
| # Optional | ||||
| # Default: true | ||||
| # | ||||
| watch = true | ||||
|  | ||||
| # Polling interval (in seconds). | ||||
| # | ||||
| # Optional | ||||
| # Default: 15 | ||||
| # | ||||
| refreshSeconds = 15 | ||||
|  | ||||
| # AccessKeyID to use when connecting to AWS. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| accessKeyID = "abc" | ||||
|  | ||||
| # SecretAccessKey to use when connecting to AWS. | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| secretAccessKey = "123" | ||||
|  | ||||
| # Endpoint of local dynamodb instance for testing? | ||||
| # | ||||
| # Optional | ||||
| # | ||||
| endpoint = "http://localhost:8080" | ||||
| ``` | ||||
|  | ||||
| ## Table Items | ||||
|  | ||||
| Items in the `dynamodb` table must have three attributes: | ||||
|  | ||||
| - `id` (string): The id is the primary key. | ||||
| - `name`(string): The name is used as the name of the frontend or backend. | ||||
| - `frontend` or `backend` (map): This attribute's structure matches exactly the structure of a Frontend or Backend type in Traefik.   | ||||
|     See `types/types.go` for details.   | ||||
|     The presence or absence of this attribute determines its type. | ||||
|     So an item should never have both a `frontend` and a `backend` attribute. | ||||
|  | ||||
Some files were not shown because too many files have changed in this diff Show More
		Reference in New Issue
	
	Block a user